CVE-2024-39367: Command Injection
An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39367?
CVE-2024-39367 has been classified as a critical vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-39367?
The vulnerability CVE-2024-39367 can be mitigated by updating the Wavlink AC3000 M33A8 firmware to the latest version provided by the vendor.
What type of vulnerability is CVE-2024-39367?
CVE-2024-39367 is an OS command injection vulnerability that can be exploited through specially crafted HTTP requests.
Who is affected by CVE-2024-39367?
CVE-2024-39367 affects users of the Wavlink AC3000 M33A8 router using the version V5030.210505.
What can an attacker achieve by exploiting CVE-2024-39367?
An attacker exploiting CVE-2024-39367 can execute arbitrary code on the system if they can send an authenticated HTTP request.