CVE-2024-38666: Critical severity wavlink jetstream ac3000 vulnerability
An external config control vulnerability exists in the openvpn.cgi openvpnclientsetup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38666?
CVE-2024-38666 is considered a high-severity vulnerability due to its potential for arbitrary command execution.
How does CVE-2024-38666 occur?
CVE-2024-38666 occurs when an attacker sends a specially crafted HTTP request to the openvpn.cgi openvpn_client_setup() functionality.
What are the potential impacts of CVE-2024-38666?
The potential impacts of CVE-2024-38666 include unauthorized command execution on affected devices.
How do I mitigate CVE-2024-38666?
To mitigate CVE-2024-38666, ensure that you apply any available security updates provided by Wavlink.
Who is affected by CVE-2024-38666?
CVE-2024-38666 affects users of the Wavlink AC3000 M33A8 with the specified firmware version.