An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability results from insufficient validation of externally controlled configuration parameters passed to the set_smb_cfg() function in the nas.cgi script. An attacker sends a specially crafted HTTP request to the vulnerable endpoint, injecting malicious values into configuration parameters, which are then executed by the system without sanitization. Authentication is required to trigger the vulnerability, but once obtained, the exploit does not require any additional user interaction.
An attacker can execute arbitrary system commands with the privileges of the process handling the request, which in practice means the possibility of complete takeover of the device, configuration modification, data leakage, and using the device as a starting point for further attacks on the network.
Patches available from the manufacturer should be applied according to the references. Until the update is applied, it is recommended to restrict access to the device's administrative interface only to trusted hosts and to avoid exposing the management panel to the public network.
Wavlink AC3000 M33A8, firmware version V5030.210505 (products: Wavlink WL-WN533A8 Firmware, Wavlink WL-WN533A8)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi