CVE-2024-39370: Critical severity wavlink jetstream ac3000 vulnerability
An arbitrary code execution vulnerability exists in the adm.cgi setMeshAp() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39370?
CVE-2024-39370 is classified as a high severity vulnerability due to its capability to allow arbitrary code execution.
How do I fix CVE-2024-39370?
To fix CVE-2024-39370, update the Wavlink AC3000 M33A8 to the latest firmware version that addresses this vulnerability.
Who is affected by CVE-2024-39370?
CVE-2024-39370 affects the Wavlink AC3000 M33A8 router model running the software version V5030.210505.
What type of attack does CVE-2024-39370 enable?
CVE-2024-39370 enables an attacker to execute arbitrary code on the affected device through a specially crafted HTTP request.
Is authentication required to exploit CVE-2024-39370?
Yes, an authenticated HTTP request is required to exploit CVE-2024-39370.