CVE-2024-34166: Command Injection
An os command injection vulnerability exists in the touchlistsync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34166?
CVE-2024-34166 is classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-34166?
To fix CVE-2024-34166, update the Wavlink AC3000 M33A8 firmware to the latest version that addresses this vulnerability.
What causes CVE-2024-34166?
CVE-2024-34166 is caused by an OS command injection vulnerability in the touchlist_sync.cgi file within the Wavlink AC3000 M33A8 device.
Who is affected by CVE-2024-34166?
CVE-2024-34166 affects users of the Wavlink AC3000 M33A8 model across the specified firmware version.
Can CVE-2024-34166 be exploited remotely?
Yes, CVE-2024-34166 can be exploited remotely through specially crafted HTTP requests.