CVE-2024-39759: Command Injection
Multiple OS command injection vulnerabilities exist in the login.cgi setsysinit() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the restarthourvalue POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39759?
CVE-2024-39759 has been assigned a high severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2024-39759?
To fix CVE-2024-39759, it is recommended to update the Wavlink AC3000 M33A8 firmware to the latest version provided by the vendor.
What kind of attack does CVE-2024-39759 enable?
CVE-2024-39759 enables attackers to execute arbitrary commands on the affected device through specially crafted HTTP requests.
Who is affected by CVE-2024-39759?
CVE-2024-39759 affects users of the Wavlink AC3000 M33A8 router using the vulnerable firmware version V5030.210505.
Is authentication required to exploit CVE-2024-39759?
No, CVE-2024-39759 can be exploited by unauthenticated attackers, making it particularly dangerous.