CRITICAL🇵🇱 Wersja polska

CVE-2024-39789

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-11-03

Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_port` POST parameter.

🤖 AI Analysis
How it works

The `set_ftp_cfg()` function in the `nas.cgi` script does not properly validate the value passed in the POST parameter `ftp_port`. An attacker who has access to an authenticated HTTP session can send a specially crafted HTTP request containing malicious data in this parameter. The lack of proper input sanitization enables injection of arbitrary configuration values, leading to permission bypass. The vulnerability has a scope extending beyond the component in which it occurs (Scope: Changed), which increases its criticality.

Impact

An attacker can bypass access control mechanisms and take control of the device configuration, potentially gaining full access to sensitive data, modifying system settings, or causing service unavailability (confidentiality, integrity, and availability — all threatened at HIGH level).

Mitigation & patch

Patches available from the manufacturer should be applied according to the references. Details regarding updates are available in the Cisco Talos Intelligence report (TALOS-2024-2056). Until the fix is implemented, it is recommended to restrict access to the device's administrative interface exclusively to trusted hosts and to apply strong, unique authentication policies.

Who is affected

Wavlink AC3000 M33A8, firmware version M33A8.V5030.210505 (products: Wavlink WL-WN533A8 / WL-WN533A8 Firmware)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi