CVE-2024-39788: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setftpcfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the ftpname POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39788?
CVE-2024-39788 is considered to have a high severity due to its potential for permission bypass.
How do I fix CVE-2024-39788?
To fix CVE-2024-39788, it is recommended to update the Wavlink AC3000 M33A8 firmware to the latest version provided by the vendor.
What are the potential impacts of CVE-2024-39788?
CVE-2024-39788 can allow unauthorized access to sensitive configurations through specially crafted HTTP requests.
Which products are affected by CVE-2024-39788?
CVE-2024-39788 affects the Wavlink AC3000 M33A8 model specifically.
Is authentication required to exploit CVE-2024-39788?
Yes, an attacker must be able to make an authenticated HTTP request to exploit CVE-2024-39788.