CVE-2024-39760: Command Injection
Multiple OS command injection vulnerabilities exist in the login.cgi setsysinit() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the restartminvalue POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39760?
CVE-2024-39760 is considered critical due to its potential for arbitrary code execution.
How do I fix CVE-2024-39760?
To fix CVE-2024-39760, apply the latest firmware update provided by Wavlink for the AC3000 M33A8 device.
Who is affected by CVE-2024-39760?
CVE-2024-39760 affects all versions of the Wavlink AC3000 M33A8 device that have the vulnerable login.cgi functionality.
What types of attacks can be performed using CVE-2024-39760?
CVE-2024-39760 allows for OS command injection, enabling attackers to execute arbitrary code through crafted HTTP requests.
Is authentication required to exploit CVE-2024-39760?
No, CVE-2024-39760 can be exploited without authentication, allowing unauthenticated attackers to execute arbitrary commands.