CVE-2024-39782: Command Injection
Multiple OS command injection vulnerabilities exist in the adm.cgi schreboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the restartmin POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39782?
CVE-2024-39782 is considered a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2024-39782?
To mitigate CVE-2024-39782, update the firmware of the Wavlink AC3000 M33A8 device to the latest version provided by the vendor.
What type of vulnerability is CVE-2024-39782?
CVE-2024-39782 is classified as an OS command injection vulnerability.
Who is affected by CVE-2024-39782?
CVE-2024-39782 affects the Wavlink AC3000 M33A8 devices running version V5030.210505.
Can CVE-2024-39782 be exploited remotely?
Yes, CVE-2024-39782 can be exploited remotely through specially crafted HTTP requests.