CVE-2024-38894: Command Injection
Published Jun 24, 2024
·Updated
WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlistsync.cgi.
Affected Software
3 affected components
Wavlink WN551K1
All of the following
Wavlink Wn551k1 Firmware
Wavlink WN551K1
Event History
Jun 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-38894?
CVE-2024-38894 has been classified as a high-severity vulnerability due to its potential for command injection.
2
How do I fix CVE-2024-38894?
To fix CVE-2024-38894, update the WAVLINK WN551K1 firmware to the latest version provided by the vendor.
3
What is the impact of CVE-2024-38894?
The impact of CVE-2024-38894 allows an attacker to execute arbitrary commands on the device by exploiting the IP parameter in the affected CGI script.
4
Which devices are affected by CVE-2024-38894?
CVE-2024-38894 affects the WAVLINK WN551K1 device specifically.
5
Is CVE-2024-38894 remotely exploitable?
Yes, CVE-2024-38894 is remotely exploitable, allowing attackers to target the device without physical access.