A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability (CWE-74) results from insufficient validation of input data passed to the AddMac() function in the wireless.cgi script. An attacker sends a specially crafted HTTP request containing a malicious payload that is interpreted as a system command. Exploitation of the vulnerability requires prior authentication on the device. Once this condition is met, execution of arbitrary commands occurs in the context of the router's operating system, and the effect may extend beyond normal session isolation (Scope: Changed).
An attacker can gain full control over the device, including reading sensitive configuration data, modifying network settings, and permanently compromising device availability. High impact level on confidentiality, integrity, and availability (C:H/I:H/A:H) indicates the possibility of complete router takeover.
Patches available from the manufacturer should be applied according to references. It is recommended to monitor updates on the manufacturer's website and review the Talos Intelligence report (TALOS-2024-2044). Until the patch is applied, it is advisable to restrict access to the device's administrative panel exclusively to trusted hosts and network segments.
Wavlink AC3000 M33A8, firmware version V5030.210505 (Wavlink WL-WN533A8 / WL-WN533A8 Firmware products)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi
Buffer overflow w Wavlink AC3000 — podatność w login.cgi (Goto_chidx)