Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `sel_open_interface` POST parameter.
The vulnerability lies in improper validation of input data passed through the POST parameter named `sel_open_interface` to the openvpn_server_setup() function in the openvpn.cgi script. An attacker can submit a specially crafted HTTP request containing malicious configuration values, which are then processed without proper sanitization. This leads to external configuration injection (CWE-15), resulting in the execution of arbitrary commands in the context of the device's operating system. The attack requires authentication; however, once obtained, it can be carried out remotely without user interaction.
A successful attack allows the attacker to remotely execute arbitrary system commands (RCE) on the device with potential full takeover of the router, which threatens the confidentiality, integrity, and availability of network resources managed by the device.
Security patches available from the manufacturer should be applied according to the references. As immediate remedial measures, it is recommended to restrict access to the device's administrative panel exclusively to trusted IP addresses and avoid exposing the management interface to the public internet.
Wavlink WL-WN533A8 devices (Wavlink AC3000 M33A8) with firmware version V5030.210505
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi