CVE-2024-20017 is an out-of-bounds write vulnerability in a WLAN service caused by improper input validation. A remote attacker may exploit the flaw to achieve code execution without requiring additional execution privileges or user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains three Python exploit scripts targeting CVE-2024-20017, a remote code execution vulnerability in the Netgear WAX206's wappd daemon (MediaTek MTK7622 platform). The exploits are architecture-specific: one for aarch64 (WAX206-aarch64/wax-rip-system-rop.py) and two for x86_64 (x86_64/x86_64_full_relro.py and x86_64/x86_64_partial_relro_got.py), though the README notes that x86_64 exploits may not work out-of-the-box on vanilla builds. All scripts use pwntools and implement advanced memory corruption techniques (arbitrary write, ROP/JOP chains, GOT overwrites) to hijack execution flow and ultimately execute a shell command on the target. The payload delivered is a reverse shell, which connects back to the attacker's machine (lhost:lport) and provides remote shell access. The exploit requires network access to the target's wappd service (default UDP/TCP port 3517) and the ability to serve a reverse shell script over HTTP. The repository is well-structured, with clear separation of architecture-specific exploits and a requirements.txt for dependencies.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.