CVE-2024-39789: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setftpcfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the ftpport POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39789?
CVE-2024-39789 is considered a high severity vulnerability due to its potential for permission bypass through authenticated HTTP requests.
How do I fix CVE-2024-39789?
To fix CVE-2024-39789, update the Wavlink AC3000 M33A8 device firmware to the latest version provided by the vendor.
What type of attacks can exploit CVE-2024-39789?
CVE-2024-39789 can be exploited by attackers making specially crafted authenticated HTTP requests that manipulate configuration controls.
Is remote access required to exploit CVE-2024-39789?
Yes, an attacker must have authenticated remote access to trigger the vulnerabilities associated with CVE-2024-39789.
Which product versions are affected by CVE-2024-39789?
CVE-2024-39789 affects the Wavlink AC3000 M33A8 model with the version V5030.210505.