Description

Wi-Fi Alliance wfa_dut (in Wi-Fi Test Suite) through 9.0.0 allows OS command injection via 802.11x frames because the system() library function is used. For example, on Arcadyan FMIMG51AX000J devices, this leads to wfaTGSendPing remote code execution as root via traffic to TCP port 8000 or 8080 on a LAN interface. On other devices, this may be exploitable over a WAN interface.

INFO

Published Date :

2024-11-11T00:00:00.000Z

Last Modified :

2024-11-12T17:16:19.610Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2024-41992 vulnerability.

Vendors Products
Wi-fi-test Suite
  • Wi-fi-test Suite
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-41992.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact