CVE-2024-10429: WAVLINK WN530H4/WN530HG4/WN572HG3 internet.cgi set_ipv6 command injection
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function setipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAddr/IPv6GWAddr leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-10429?
CVE-2024-10429 is classified as a critical vulnerability.
How do I fix CVE-2024-10429?
To fix CVE-2024-10429, update the affected WAVLINK devices to the firmware versions released after October 28, 2022.
Which devices are affected by CVE-2024-10429?
CVE-2024-10429 affects WAVLINK models WN530H4, WN530HG4, and WN572HG3 with specific firmware versions.
What type of vulnerability is CVE-2024-10429?
CVE-2024-10429 is a command injection vulnerability found in the set_ipv6 function of the internet.cgi file.
What are the potential impacts of CVE-2024-10429?
The exploitation of CVE-2024-10429 can lead to unauthorized command execution on the affected WAVLINK devices.