CRITICAL🇵🇱 Wersja polska

CVE-2024-39280

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-08-21

An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation of externally controlled configuration parameters passed to the set_smb_cfg() function in the nas.cgi script. An attacker sends a specially crafted HTTP request to the vulnerable endpoint, injecting malicious values into configuration parameters, which are then executed by the system without sanitization. Authentication is required to trigger the vulnerability, but once obtained, the exploit does not require any additional user interaction.

Impact

An attacker can execute arbitrary system commands with the privileges of the process handling the request, which in practice means the possibility of complete takeover of the device, configuration modification, data leakage, and using the device as a starting point for further attacks on the network.

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Until the update is applied, it is recommended to restrict access to the device's administrative interface only to trusted hosts and to avoid exposing the management panel to the public network.

Who is affected

Wavlink AC3000 M33A8, firmware version V5030.210505 (products: Wavlink WL-WN533A8 Firmware, Wavlink WL-WN533A8)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi