An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
The vulnerability is located in the set_nas() function of the nas.cgi file in Wavlink AC3000 M33A8 firmware version V5030.210505. The attacker sends a specially crafted HTTP request to the nas.cgi endpoint, which contains malicious data controlling the external configuration. Insufficient input validation causes the passed values to be interpreted as system commands and executed by the device. Authentication to the device interface is required to trigger the vulnerability.
An authenticated attacker can execute arbitrary commands (RCE) on the device, gaining full control over its configuration, data, and the network to which it is connected. The consequence may be a breach of data confidentiality and integrity as well as loss of device availability.
Apply patches available from the manufacturer according to the references. Until an update is applied, it is recommended to restrict access to the device's administrative interface to trusted IP addresses only and to disable remote management over the Internet.
Wavlink AC3000 M33A8 (WL-WN533A8 / WL-WN533A8 Firmware products) in firmware version V5030.210505
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi