CRITICAL🇵🇱 Wersja polska

CVE-2024-39798

CVSS 9.1v3.1pub. 2025-01-14upd. 2025-11-03

Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_protocol` POST parameter.

🤖 AI Analysis
How it works

The vulnerability affects the POST parameter `sel_open_protocol` passed to the openvpn_server_setup() function in the openvpn.cgi script. Lack of proper validation and sanitization of input data means that a specially crafted HTTP request can inject malicious configuration directives (configuration injection), which consequently leads to execution of arbitrary system commands. The attack requires authentication, but does not require user interaction and is performed remotely over the network.

Impact

Successful exploitation of this vulnerability allows an attacker to remotely execute arbitrary commands (RCE) on the device, which may result in complete takeover of the router, violation of data confidentiality and integrity, and disruption of network service availability.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Additionally, it is recommended to restrict access to the device's administrative panel only to trusted IP addresses and to avoid exposing the management interface to the public network.

Who is affected

Wavlink AC3000 M33A8 with firmware version M33A8.V5030.210505 (products: Wavlink WL-WN533A8 / Wavlink WL-WN533A8 Firmware)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Wavlink Wl Wn533a8

    HW
    Wavlink
    all versions
  • Wavlink Wl Wn533a8 Firmware

    OS
    Wavlink
    m33a8.v5030.210505
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
VPN
CWE
References

Related vulnerabilities

CVE-2024-21797CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi

CVE-2024-34166CRITICAL10.0PL ✓same product

Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu

CVE-2024-34544CRITICAL9.1PL ✓same product

Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń

CVE-2024-36258CRITICAL10.0PL ✓same product

Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP

CVE-2024-36272CRITICAL9.1PL ✓same product

Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi