CVE-2024-39803: Buffer Overflow
Multiple buffer overflow vulnerabilities exist in the qos.cgi qossettings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the selmode POST parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39803?
CVE-2024-39803 is rated as a critical vulnerability due to its potential to allow remote attackers to execute arbitrary code.
How can I mitigate CVE-2024-39803?
To mitigate CVE-2024-39803, apply security patches provided by Wavlink for the AC3000 M33A8 device.
What are the potential impacts of CVE-2024-39803?
The potential impacts of CVE-2024-39803 include unauthorized data access, system crashes, and remote code execution.
Who is affected by CVE-2024-39803?
CVE-2024-39803 affects users of the Wavlink AC3000 M33A8 device running the firmware version V5030.210505.
How is CVE-2024-39803 exploited?
CVE-2024-39803 can be exploited by attackers sending specially crafted HTTP requests to the qos.cgi qos_settings() function.