CVE-2024-39794: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setnas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the ftpport POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39794?
CVE-2024-39794 has a medium severity rating due to its potential for permission bypass.
How do I fix CVE-2024-39794?
To fix CVE-2024-39794, update your Wavlink AC3000 M33A8 or ProFTPD firmware to the latest version that addresses these vulnerabilities.
What type of attack can exploit CVE-2024-39794?
CVE-2024-39794 can be exploited through a specially crafted HTTP request that targets the nas.cgi set_nas() functionality.
Which devices are affected by CVE-2024-39794?
CVE-2024-39794 affects the Wavlink AC3000 M33A8 and the Wavlink ProFTPD.
Can an attacker trigger CVE-2024-39794 without authentication?
No, an attacker needs to be authenticated to exploit CVE-2024-39794.