CVE-2024-41992: Unpatched Zero-Day RCE Flaw Found in Arcadyan Routers

Red | Vulnerability Report
Download PDF

CVE-2024-41992 is a severe zero-day vulnerability in the Arcadyan FMIMG51AX000J and potentially other WiFi Alliance devices using the same firmware, allowing remote code execution. The flaw stems from a test utility service on ports 8000 and 8080, which mishandles TLV packets, enabling command injection. A proof-of-concept exploit has been released, and despite being reported in April 2024, no fix is available. Users are advised to restrict remote access and isolate affected devices until a patch is provided.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox