A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
The vulnerability lies in the set_lang_CountryCode() function handled by the login.cgi file in the device firmware. An unauthenticated attacker sends a specially crafted HTTP request containing a malicious XSS payload. The device processes the input without proper filtering or encoding, leading to execution of malicious code on the user's browser side and disclosure of sensitive information. The vulnerability is classified as CWE-80 (Improper Neutralization of Script-Related HTML Tags in a Web Page), which means a lack of neutralization of script tags in the generated page.
An attacker can cause disclosure of sensitive information available in the victim's browser context, including potentially session data or login credentials. Due to the CVSS rating indicating high impact on confidentiality, integrity and availability, as well as Changed Scope (C), the consequences may extend beyond the vulnerable component itself.
Apply patches available from the manufacturer in accordance with the references. Details regarding the patched firmware version are available in the Cisco Talos Intelligence report (TALOS-2024-2017). Until an update is applied, it is recommended to restrict access to the device management interface only to trusted networks and to disable access to the admin panel from the WAN.
Wavlink AC3000 M33A8 firmware, version V5030.210505 (Wavlink WL-WN533A8 devices).
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi