CVE-2024-39765: Command Injection
Multiple OS command injection vulnerabilities exist in the internet.cgi setaddrouting() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the custominterface POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39765?
CVE-2024-39765 is considered a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2024-39765?
To mitigate CVE-2024-39765, update to the latest firmware version provided by Wavlink for the AC3000 model.
What systems are affected by CVE-2024-39765?
CVE-2024-39765 affects the Wavlink AC3000 model with version V5030.210505.
What type of vulnerability is CVE-2024-39765?
CVE-2024-39765 is classified as an OS command injection vulnerability.
Can CVE-2024-39765 be exploited remotely?
Yes, CVE-2024-39765 can be exploited remotely by sending specially crafted HTTP requests to the vulnerable device.