CVE-2024-39784: Command Injection
Multiple command execution vulnerabilities exist in the nas.cgi adddir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the diskpart POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39784?
CVE-2024-39784 has a high severity due to the potential for arbitrary command execution.
How do I fix CVE-2024-39784?
To address CVE-2024-39784, update the Wavlink AC3000 M33A8 firmware to the latest version.
What types of attacks can exploit CVE-2024-39784?
CVE-2024-39784 can be exploited through specially crafted HTTP requests that lead to command injection.
Who is affected by CVE-2024-39784?
CVE-2024-39784 affects users of the Wavlink AC3000 M33A8 router model.
Is user authentication required to exploit CVE-2024-39784?
Yes, an attacker must make an authenticated HTTP request to exploit CVE-2024-39784.