Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `open_port` POST parameter.
The vulnerability consists of insufficient validation of the POST parameter named `open_port`, passed to the openvpn_server_setup() function in the openvpn.cgi script. An attacker who has access to an authenticated HTTP session can craft a specially prepared HTTP request containing malicious values in this parameter. The injected data is then processed as part of the configuration in a way that allows arbitrary system commands to be executed (command injection through the configuration injection mechanism).
An authenticated attacker can execute arbitrary system commands on the vulnerable device, which in practice means the possibility of complete takeover of the router, violation of data confidentiality and integrity, and disruption of network service availability.
Patches available from the manufacturer should be applied in accordance with the references. Additionally, it is recommended to restrict access to the device management interface only to trusted IP addresses and avoid exposing the admin panel to public access over the Internet.
Wavlink AC3000 routers (WL-WN533A8 models) with firmware version M33A8.V5030.210505
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HWavlink Wl Wn533a8
HWWavlinkall versionsWavlink Wl Wn533a8 Firmware
OSWavlinkm33a8.v5030.210505
Related vulnerabilities
Command injection w Wavlink AC3000 — wykonanie dowolnych poleceń przez adm.cgi
Command injection w firmware Wavlink AC3000 — zdalne wykonanie kodu
Command injection w Wavlink AC3000 – nieautoryzowane wykonanie poleceń
Stack-based buffer overflow w Wavlink AC3000 umożliwia RCE przez HTTP
Buffer overflow w Wavlink AC3000 — podatność w funkcji set_info() usbip.cgi