CRITICAL🇵🇱 Wersja polska

CVE-2024-39790

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-11-03

Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_max_sessions` POST parameter.

🤖 AI Analysis
How it works

The vulnerability concerns a POST parameter named ftp_max_sessions, passed to the set_ftp_cfg() function in the nas.cgi script. This function does not properly validate the value supplied by the user, which enables injection of malicious configuration directives (CWE-15 — External Control of System or Configuration Setting). An attacker possessing credentials to the management panel can send a specially crafted HTTP request, which will cause permission control mechanisms to be bypassed and dangerous configuration to be saved on the device.

Impact

Successful exploitation of this vulnerability allows an attacker to perform unauthorized modification of system configuration, which may lead to complete takeover of the device, loss of confidentiality, integrity, and availability of supported network resources.

Mitigation & patch

Apply patches available from the manufacturer according to references. It is recommended to monitor Wavlink manufacturer updates and Cisco Talos security advisory (TALOS-2024-2056). Temporarily restrict access to the device's administrative panel exclusively to trusted IP addresses and disable unnecessary network services (e.g., FTP) if not required.

Who is affected

Wavlink AC3000 devices (WL-WN533A8 models) with firmware version M33A8.V5030.210505

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi