CRITICAL🇵🇱 Wersja polska

CVE-2024-38666

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-08-21

An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability is located in the openvpn_client_setup() function of the openvpn.cgi file, responsible for configuring the OpenVPN client. The application improperly controls externally supplied configuration data (CWE-15), which allows it to be smuggled into system calls. The attacker must have an authenticated HTTP session and send a specially crafted request that causes arbitrary command execution in the context of the device's operating system.

Impact

An attacker with access to an authenticated session can execute arbitrary operating system commands on the device, leading to complete takeover of the router, disclosure of sensitive data, and potential compromise of the integrity of the network served by the device.

Mitigation & patch

Security patches available from the manufacturer should be applied according to the references. It is recommended to restrict access to the device's administrative panel only to trusted IP addresses and to disable remote management if it is not necessary.

Who is affected

Wavlink AC3000 M33A8 with firmware version V5030.210505 (Wl-Wn533A8 / Wl-Wn533A8 Firmware products).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi