CVE-2024-21797: Critical severity wavlink jetstream ac3000 vulnerability
A command execution vulnerability exists in the adm.cgi setTR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21797?
CVE-2024-21797 is considered a high severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2024-21797?
To mitigate CVE-2024-21797, update the Wavlink AC3000 M33A8 firmware to the latest version available from the vendor.
When was CVE-2024-21797 discovered?
CVE-2024-21797 was reported in 2024, highlighting a vulnerability in the adm.cgi set_TR069() functionality.
What type of vulnerability is CVE-2024-21797?
CVE-2024-21797 is classified as a command execution vulnerability.
Who is affected by CVE-2024-21797?
CVE-2024-21797 affects users of the Wavlink AC3000 M33A8 device that are utilizing the vulnerable firmware version.