CVE-2024-39781: Command Injection
Multiple OS command injection vulnerabilities exist in the adm.cgi schreboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the restarthour POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39781?
CVE-2024-39781 is considered a high severity vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2024-39781?
To fix CVE-2024-39781, update the Wavlink AC3000 M33A8 firmware to the latest version provided by the vendor.
Who is affected by CVE-2024-39781?
CVE-2024-39781 affects users of the Wavlink AC3000 M33A8 router with the specified firmware version.
What type of vulnerability is CVE-2024-39781?
CVE-2024-39781 is classified as an OS command injection vulnerability.
Can CVE-2024-39781 be exploited remotely?
Yes, CVE-2024-39781 can be exploited remotely if the attacker has the ability to make authenticated HTTP requests.