CVE-2024-39793: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setnas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the ftpname POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39793?
CVE-2024-39793 has a critical severity rating due to its potential for permission bypass in external configuration controls.
How do I fix CVE-2024-39793?
To fix CVE-2024-39793, update the Wavlink AC3000 M33A8 firmware to the latest version that addresses these vulnerabilities.
What types of attacks can exploit CVE-2024-39793?
CVE-2024-39793 can be exploited through specially crafted HTTP requests that bypass existing permissions.
Which products are affected by CVE-2024-39793?
CVE-2024-39793 affects the Wavlink AC3000 M33A8 and its ProFTPD functionality.
Is CVE-2024-39793 remotely exploitable?
Yes, CVE-2024-39793 can be remotely exploited by authenticated attackers through the vulnerability in the nas.cgi set_nas() functionality.