Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_max_sessions` POST parameter.
The vulnerability affects the POST parameter `ftp_max_sessions` handled by the set_nas() function in nas.cgi. An attacker who has access to an authenticated HTTP session can submit a specially crafted HTTP request containing a maliciously formatted parameter value. This causes injection of unintended directives into the proftpd server configuration file (CWE-15: External Control of System or Configuration Setting), bypassing the expected permission control mechanisms.
An attacker can take control of the FTP server configuration running on the device, which in the context of a network vector and changed scope (Scope: Changed) may lead to complete loss of confidentiality, integrity, and availability of data and device functions.
Apply patches available from the manufacturer according to the references. As an interim risk mitigation measure, it is recommended to restrict access to the device's administrative interface exclusively to trusted IP addresses and to avoid exposing the management panel to the public network.
Wavlink AC3000 device (WL-WN533A8 models) with firmware version M33A8.V5030.210505.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi