Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_name` POST parameter.
The vulnerability lies in the lack of proper validation and sanitization of the ftp_name parameter value passed in an HTTP POST request to the nas.cgi endpoint. An attacker who has access to an authenticated session can craft a specially constructed HTTP request that injects arbitrary configuration into the proftpd service running on the device. The set_nas() mechanism processes input data without appropriate controls, allowing permission bypass and manipulation of the FTP server's external configuration.
An attacker can bypass permission mechanisms, modify the proftpd service configuration and — according to the CVSS vector (S:C, C:H, I:H, A:H) — gain full control over the device with the ability to compromise the confidentiality, integrity and availability of the system, including data stored on the connected NAS resource.
Apply patches available from the manufacturer according to the references. As temporary mitigation, it is recommended to restrict access to the device's administrative panel exclusively to trusted local networks and disable NAS/FTP functionality if not required.
Wavlink AC3000 devices (model WL-WN533A8) with firmware version M33A8.V5030.210505
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi