CRITICAL🇵🇱 Wersja polska

CVE-2024-39794

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-11-03

Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_port` POST parameter.

🤖 AI Analysis
How it works

The vulnerability lies in improper handling of the POST parameter `ftp_port` in the set_nas() function handled by the nas.cgi script in Wavlink AC3000 firmware (version M33A8.V5030.210505). An attacker sends a crafted HTTP request containing malicious values in the `ftp_port` parameter, leading to injection of unauthorized configuration values into the ProFTPD service. As a result, it is possible to bypass permission control mechanisms (permission bypass) without requiring higher-level administrator privileges — standard user-level authentication is sufficient.

Impact

An attacker can modify the ProFTPD service configuration in a way that exceeds their assigned permissions, which may lead to unauthorized access to NAS device resources, breach of confidentiality and integrity of stored data, and potentially service destabilization (high impact rating on C, I, and A in the CVSS vector).

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is recommended to restrict access to the device management interface to trusted networks only and monitor unexpected HTTP requests directed to nas.cgi. Details regarding available updates should be verified in the Cisco Talos report: TALOS-2024-2053.

Who is affected

Wavlink AC3000 devices with firmware version M33A8.V5030.210505 (products: Wavlink WL-WN533A8 Firmware, Wavlink WL-WN533A8).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi