CVE-2024-39768: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the internet.cgi setqos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the cliname POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39768?
CVE-2024-39768 is classified as a high severity vulnerability due to its potential for exploitation through stack-based buffer overflow.
How do I fix CVE-2024-39768?
To address CVE-2024-39768, ensure that you are using the latest firmware version of the Wavlink AC3000 M33A8 and apply any security patches released by the vendor.
Who is affected by CVE-2024-39768?
CVE-2024-39768 affects Wavlink AC3000 M33A8 devices running version V5030.210505.
What kind of attack can exploit CVE-2024-39768?
CVE-2024-39768 can be exploited through a specially crafted authenticated HTTP request targeting the internet.cgi set_qos() functionality.
What are the potential consequences of CVE-2024-39768?
Exploitation of CVE-2024-39768 may allow an attacker to execute arbitrary code or cause denial of service on the affected device.