CVE-2024-39799: Critical severity wavlink jetstream ac3000 vulnerability
Multiple external config control vulnerabilities exists in the openvpn.cgi openvpnserversetup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the selopeninterface POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39799?
CVE-2024-39799 is considered a high severity vulnerability due to its potential for arbitrary command execution.
How do I fix CVE-2024-39799?
To fix CVE-2024-39799, update to the latest firmware version provided by Wavlink for the AC3000 M33A8.
What impact does CVE-2024-39799 have on my system?
CVE-2024-39799 can allow an authenticated attacker to execute arbitrary commands on the vulnerable system.
How does an attacker exploit CVE-2024-39799?
An attacker can exploit CVE-2024-39799 by sending a specially crafted HTTP request to the vulnerable openvpn.cgi script.
Is CVE-2024-39799 specific to certain versions of Wavlink products?
Yes, CVE-2024-39799 specifically affects the Wavlink AC3000 M33A8 running version V5030.210505.