CVE-2024-39761: Command Injection
Multiple OS command injection vulnerabilities exist in the login.cgi setsysinit() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an unauthenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists within the restartweekvalue POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39761?
CVE-2024-39761 has been assigned a critical severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2024-39761?
To fix CVE-2024-39761, apply the recommended firmware updates from Wavlink that address the OS command injection vulnerabilities.
What products are affected by CVE-2024-39761?
CVE-2024-39761 affects the Wavlink AC3000 M33A8 model specifically in version V5030.210505.
Can CVE-2024-39761 be exploited remotely?
Yes, CVE-2024-39761 can be exploited remotely through unauthenticated HTTP requests.
What are the potential consequences of CVE-2024-39761?
The potential consequences of CVE-2024-39761 include unauthorized access and execution of arbitrary commands on the affected device.