CVE-2024-39769: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the internet.cgi setqos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.This vulnerability exists in the climac POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39769?
CVE-2024-39769 has a high severity rating due to the potential for stack-based buffer overflow and subsequent unauthorized access.
How do I fix CVE-2024-39769?
To mitigate CVE-2024-39769, apply available firmware updates from Wavlink that address the vulnerabilities in the internet.cgi functionality.
Who is affected by CVE-2024-39769?
CVE-2024-39769 affects users of the Wavlink AC3000 M33A8 router running version V5030.210505.
Can CVE-2024-39769 be exploited remotely?
Yes, CVE-2024-39769 can be exploited remotely by sending specially crafted HTTP requests to the vulnerable device.
What type of vulnerabilities does CVE-2024-39769 include?
CVE-2024-39769 includes multiple buffer overflow vulnerabilities specifically within the set_qos() functionality of the affected device.