CVE-2024-39801: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the qos.cgi qossettings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the qosbandwidth POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39801?
CVE-2024-39801 has been classified as a high severity vulnerability due to its potential to allow remote code execution through buffer overflow.
How do I fix CVE-2024-39801?
To mitigate CVE-2024-39801, users should update the Wavlink AC3000 M33A8 firmware to the latest version provided by Wavlink.
Who is affected by CVE-2024-39801?
CVE-2024-39801 affects Wavlink AC3000 M33A8 devices running firmware version V5030.210505.
What are the potential impacts of CVE-2024-39801?
Exploitation of CVE-2024-39801 can lead to unauthorized access, system crashes, or remote code execution on the affected devices.
Is CVE-2024-39801 exploitable remotely?
Yes, CVE-2024-39801 can be exploited remotely by sending specially crafted HTTP requests to the affected Wavlink AC3000 M33A8 device.