CVE-2024-39785: Command Injection
Multiple command execution vulnerabilities exist in the nas.cgi adddir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the adddirname POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39785?
CVE-2024-39785 is classified as a critical vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2024-39785?
To fix CVE-2024-39785, update your Wavlink AC3000 M33A8.V5030.210505 firmware to the latest version provided by Wavlink.
What causes CVE-2024-39785?
CVE-2024-39785 is caused by multiple command execution vulnerabilities in the add_dir() function of nas.cgi.
Who is affected by CVE-2024-39785?
CVE-2024-39785 affects users of the Wavlink AC3000 M33A8.V5030.210505 device.
Can CVE-2024-39785 be exploited remotely?
Yes, CVE-2024-39785 can be exploited remotely through a specially crafted HTTP request.