CVE-2024-39795: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exist in the nas.cgi setnas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the ftpmaxsessions POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39795?
CVE-2024-39795 is considered a high-severity vulnerability due to its potential to allow permission bypass.
How do I fix CVE-2024-39795?
To fix CVE-2024-39795, update the Wavlink AC3000 M33A8 or ProFTPD to the latest versions that address these vulnerabilities.
Who is affected by CVE-2024-39795?
CVE-2024-39795 affects users of the Wavlink AC3000 M33A8 and ProFTPD products.
What types of attacks can be executed using CVE-2024-39795?
Exploiting CVE-2024-39795 can lead to permission bypass through specially crafted HTTP requests.
Is authentication required to exploit CVE-2024-39795?
Yes, an authenticated HTTP request is required to trigger the vulnerabilities described in CVE-2024-39795.