CVE-2024-39602: Critical severity wavlink jetstream ac3000 vulnerability
An external config control vulnerability exists in the nas.cgi setnas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39602?
CVE-2024-39602 is considered critical due to its ability to allow arbitrary command execution via crafted HTTP requests.
How do I fix CVE-2024-39602?
To fix CVE-2024-39602, update the Wavlink AC3000 M33A8 to the latest firmware version provided by the vendor.
What systems are affected by CVE-2024-39602?
CVE-2024-39602 affects the Wavlink AC3000 M33A8 model running specific firmware versions.
How can an attacker exploit CVE-2024-39602?
An attacker can exploit CVE-2024-39602 by sending a specially crafted HTTP request that triggers command execution.
Is authentication required to exploit CVE-2024-39602?
Yes, an authenticated HTTP request is necessary to exploit CVE-2024-39602.