CVE-2024-39280: Critical severity wavlink jetstream ac3000 vulnerability
An external config control vulnerability exists in the nas.cgi setsmbcfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39280?
CVE-2024-39280 is categorized as a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2024-39280?
To mitigate CVE-2024-39280, it is recommended to update the firmware of Wavlink AC3000 to the latest version provided by the vendor.
Who is affected by CVE-2024-39280?
CVE-2024-39280 affects Wavlink AC3000 devices running the firmware version m33a8.v5030.210505.
What type of vulnerability is CVE-2024-39280?
CVE-2024-39280 is an external config control vulnerability that allows for arbitrary command execution via crafted HTTP requests.
What is the impact of exploiting CVE-2024-39280?
Exploiting CVE-2024-39280 can lead to unauthorized command execution on the affected Wavlink AC3000 device.