An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability is located in the openvpn_client_setup() function of the openvpn.cgi file, responsible for configuring the OpenVPN client. The application improperly controls externally supplied configuration data (CWE-15), which allows it to be smuggled into system calls. The attacker must have an authenticated HTTP session and send a specially crafted request that causes arbitrary command execution in the context of the device's operating system.
An attacker with access to an authenticated session can execute arbitrary operating system commands on the device, leading to complete takeover of the router, disclosure of sensitive data, and potential compromise of the integrity of the network served by the device.
Security patches available from the manufacturer should be applied according to the references. It is recommended to restrict access to the device's administrative panel only to trusted IP addresses and to disable remote management if it is not necessary.
Wavlink AC3000 M33A8 with firmware version V5030.210505 (Wl-Wn533A8 / Wl-Wn533A8 Firmware products).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi