CRITICAL🇵🇱 Wersja polska

CVE-2024-34544

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-08-21

A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability (CWE-74) results from insufficient validation of input data passed to the AddMac() function in the wireless.cgi script. An attacker sends a specially crafted HTTP request containing a malicious payload that is interpreted as a system command. Exploitation of the vulnerability requires prior authentication on the device. Once this condition is met, execution of arbitrary commands occurs in the context of the router's operating system, and the effect may extend beyond normal session isolation (Scope: Changed).

Impact

An attacker can gain full control over the device, including reading sensitive configuration data, modifying network settings, and permanently compromising device availability. High impact level on confidentiality, integrity, and availability (C:H/I:H/A:H) indicates the possibility of complete router takeover.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. It is recommended to monitor updates on the manufacturer's website and review the Talos Intelligence report (TALOS-2024-2044). Until the patch is applied, it is advisable to restrict access to the device's administrative panel exclusively to trusted hosts and network segments.

Who is affected

Wavlink AC3000 M33A8, firmware version V5030.210505 (Wavlink WL-WN533A8 / WL-WN533A8 Firmware products)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi

CVE-2024-36290CRITICAL10.0PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w login.cgi (Goto_chidx)