CVE-2024-41992 is an OS command injection vulnerability in the Wi-Fi Alliance wfa_dut component of the Wi-Fi Test Suite through version 9.0.0. The vulnerability arises from the use of the system() library function to process 802.11x frames, allowing attackers to inject arbitrary commands. On Arcadyan FMIMG51AX000J devices, this can be exploited for remote code execution as root via the wfaTGSendPing functionality, accessible through TCP port 8000 or 8080 on a LAN interface. Other devices may be vulnerable via WAN interfaces as well.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept exploit for CVE-2024-41992. It consists of four files: a README, a bash script ('a'), a Python exploit script ('exploit.py'), and a Python HTTP server ('server.py'). The main exploit workflow is as follows: - 'exploit.py' crafts and sends a TLV-encoded payload to a target device at 192.168.1.1:8080, exploiting the CVE-2024-41992 vulnerability. The payload instructs the target to execute a shell command that downloads and runs a script from the attacker's HTTP server (192.168.1.247:4). - The script ('a') downloaded by the target performs several actions: it downloads additional binaries ('db' and 'dbk'), sets up SSH access by generating keys and injecting an attacker's public key, starts a dropbear SSH server, and exfiltrates output back to the attacker's server. - 'server.py' implements a simple HTTP server that serves the required files and receives exfiltrated data via POST requests. The exploit demonstrates remote code execution, SSH backdoor installation, and data exfiltration. The attack vector is network-based, requiring the attacker to host a server and the target to be vulnerable and reachable. The repository is operational, providing a working exploit chain but requiring some setup (e.g., hosting binaries and keys).
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.