CVE-2024-39790: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setftpcfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the ftpmaxsessions POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39790?
CVE-2024-39790 has been classified as a high severity vulnerability due to the potential for permission bypass.
How do I fix CVE-2024-39790?
To mitigate CVE-2024-39790, ensure that the firmware for Wavlink AC3000 M33A8 is updated to the latest version provided by the vendor.
What type of attacks can exploit CVE-2024-39790?
CVE-2024-39790 can be exploited through specially crafted HTTP requests that bypass existing permissions.
Who is affected by CVE-2024-39790?
CVE-2024-39790 affects users of the Wavlink AC3000 M33A8 router running version V5030.210505.
Is CVE-2024-39790 a remote or local vulnerability?
CVE-2024-39790 is considered a remote vulnerability, as it can be exploited through network access to the affected device.