A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability affects the set_TR069() function in the adm.cgi file that handles the device's administrative panel. Sending an appropriately crafted HTTP request to this endpoint causes unverified commands to be executed at the operating system level of the device (command injection, CWE-74). Exploitation of the vulnerability requires authentication, but once obtained, the attacker can inject and execute arbitrary code without further restrictions. The vulnerability has scope that extends beyond the application context (Scope: Changed), which means the ability to affect resources outside the web application itself.
Successful exploitation of the vulnerability allows an attacker to gain full control over the device, including reading and modifying configuration data, persistent disruption of network services availability, and potential use of the router as an entry point to the local network.
Patches available from the manufacturer should be applied in accordance with the references. Additionally, it is recommended to restrict access to the device's administrative panel exclusively to trusted IP addresses and to avoid exposing the management interface directly to the Internet.
Wavlink AC3000 M33A8, firmware version V5030.210505 (products: Wavlink WL-WN533A8 / WL-WN533A8 Firmware)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi
Buffer overflow w Wavlink AC3000 — podatność w login.cgi (Goto_chidx)