CRITICAL🇵🇱 Wersja polska

CVE-2024-39788

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-11-03

Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_name` POST parameter.

🤖 AI Analysis
How it works

The vulnerability results from insufficient validation of input data passed through the POST parameter ftp_name to the set_ftp_cfg() function in the nas.cgi script. By sending a specially crafted HTTP request, an authenticated attacker can inject malicious values into the device's configuration file. This mechanism allows bypassing applicable permission restrictions (permission bypass), which corresponds to CWE-15 classification (External Control of System or Configuration Setting).

Impact

An attacker with access to an account on the device can modify system configuration, leading to complete compromise of confidentiality, integrity and availability of the device, including potential takeover of FTP service and other NAS functions.

Mitigation & patch

Apply patches available from the manufacturer according to references. As a temporary measure, it is recommended to restrict access to the device's administrative interface only to trusted hosts and disable FTP/NAS functionality if not required.

Who is affected

Wavlink AC3000 (model WL-WN533A8) with firmware M33A8.V5030.210505

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi