CRITICAL🇵🇱 Wersja polska

CVE-2024-39363

CVSS 9.6v3.1pub. 2025-01-14upd. 2025-08-25

A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability lies in the set_lang_CountryCode() function handled by the login.cgi file in the device firmware. An unauthenticated attacker sends a specially crafted HTTP request containing a malicious XSS payload. The device processes the input without proper filtering or encoding, leading to execution of malicious code on the user's browser side and disclosure of sensitive information. The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page), which means a lack of neutralization of script tags in the generated page.

Impact

An attacker can cause disclosure of sensitive information available in the victim's browser context, including potentially session data or login credentials. Due to the CVSS rating indicating high impact on confidentiality, integrity and availability, as well as Changed Scope (C), the consequences may extend beyond the vulnerable component itself.

Mitigation & patch

Apply patches available from the manufacturer in accordance with the references. Details regarding the patched firmware version are available in the Cisco Talos Intelligence report (TALOS-2024-2017). Until an update is applied, it is recommended to restrict access to the device management interface only to trusted networks and to disable access to the admin panel from the WAN.

Who is affected

Wavlink AC3000 M33A8 firmware, version V5030.210505 (Wavlink WL-WN533A8 devices).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi