CRITICAL🇵🇱 Wersja polska

CVE-2024-39602

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-08-21

An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability is located in the set_nas() function of the nas.cgi file in Wavlink AC3000 M33A8 firmware version V5030.210505. The attacker sends a specially crafted HTTP request to the nas.cgi endpoint, which contains malicious data controlling the external configuration. Insufficient input validation causes the passed values to be interpreted as system commands and executed by the device. Authentication to the device interface is required to trigger the vulnerability.

Impact

An authenticated attacker can execute arbitrary commands (RCE) on the device, gaining full control over its configuration, data, and the network to which it is connected. The consequence may be a breach of data confidentiality and integrity as well as loss of device availability.

Mitigation & patch

Apply patches available from the manufacturer according to the references. Until an update is applied, it is recommended to restrict access to the device's administrative interface to trusted IP addresses only and to disable remote management over the Internet.

Who is affected

Wavlink AC3000 M33A8 (WL-WN533A8 / WL-WN533A8 Firmware products) in firmware version V5030.210505

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi