CVE-2024-39608: Critical severity wavlink jetstream ac3000 vulnerability
A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39608?
CVE-2024-39608 has a high severity rating due to its potential for arbitrary firmware updates.
How do I fix CVE-2024-39608?
To fix CVE-2024-39608, update your Wavlink AC3000 M33A8 firmware to the latest version provided by the manufacturer.
What systems are affected by CVE-2024-39608?
CVE-2024-39608 affects the Wavlink AC3000 M33A8 router with firmware versions V5030.210505.
What kind of attack can exploit CVE-2024-39608?
CVE-2024-39608 can be exploited via a specially crafted HTTP request that allows arbitrary firmware updates.
Is authentication required to exploit CVE-2024-39608?
No, CVE-2024-39608 can be exploited without authentication, making it particularly dangerous.