Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_name` POST parameter.
The vulnerability results from insufficient validation of input data passed through the POST parameter ftp_name to the set_ftp_cfg() function in the nas.cgi script. By sending a specially crafted HTTP request, an authenticated attacker can inject malicious values into the device's configuration file. This mechanism allows bypassing applicable permission restrictions (permission bypass), which corresponds to CWE-15 classification (External Control of System or Configuration Setting).
An attacker with access to an account on the device can modify system configuration, leading to complete compromise of confidentiality, integrity and availability of the device, including potential takeover of FTP service and other NAS functions.
Apply patches available from the manufacturer according to references. As a temporary measure, it is recommended to restrict access to the device's administrative interface only to trusted hosts and disable FTP/NAS functionality if not required.
Wavlink AC3000 (model WL-WN533A8) with firmware M33A8.V5030.210505
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi