A buffer overflow vulnerability exists in the usbip.cgi set_info() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability results from a CWE-120 error — lack of proper validation of the size of data copied to a stack buffer (stack-based buffer overflow). An attacker possessing authentication credentials to the device's administrative panel sends a specially crafted HTTP request to the usbip.cgi endpoint. Excess data overflows the stack buffer, which can lead to hijacking control of program execution flow.
Successful exploitation of the vulnerability may allow an attacker to execute arbitrary code remotely (RCE) on the device with the privilege level of the process handling the request. As a result, complete takeover of the router is possible, as well as breach of data confidentiality and integrity, and disruption of its availability.
Apply patches available from the manufacturer according to the references. As interim remedial measures, it is recommended to restrict access to the device's administrative panel exclusively to trusted IP addresses and avoid exposing the management interface on a public network.
Wavlink AC3000 M33A8 devices with firmware version V5030.210505 (Wl-Wn533A8 / Wl-Wn533A8 Firmware products).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w login.cgi (Goto_chidx)