CVE-2024-41992 is a severe zero-day vulnerability in the Arcadyan FMIMG51AX000J and potentially other WiFi Alliance devices using the same firmware, allowing remote code execution. The flaw stems from a test utility service on ports 8000 and 8080, which mishandles TLV packets, enabling command injection. A proof-of-concept exploit has been released, and despite being reported in April 2024, no fix is available. Users are advised to restrict remote access and isolate affected devices until a patch is provided.
Get through updates and upcoming events, and more directly in your inbox