CVE-2024-39963: Command Injection
AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 V22.03.01.46 and AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 V1.0 V22.03.01.46 were discovered to contain an authenticated remote command execution (RCE) vulnerability via the macFilterType parameter at /goform/setMacFilterCfg.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39963?
CVE-2024-39963 has been classified with a high severity rating due to its potential for authenticated remote command execution.
How do I fix CVE-2024-39963?
To remediate CVE-2024-39963, update the affected AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 and AX12 to the latest firmware version that addresses this vulnerability.
What is the impact of CVE-2024-39963?
The impact of CVE-2024-39963 could allow an authenticated attacker to execute arbitrary commands on the affected routers, compromising their security.
Which devices are affected by CVE-2024-39963?
CVE-2024-39963 affects the AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX9 running firmware version 22.03.01.46 and the AX3000 Dual-Band Gigabit Wi-Fi 6 Router AX12 version 1.0 running the same firmware.
Is there a workaround for CVE-2024-39963?
Currently, there are no specific workarounds for CVE-2024-39963 other than updating the router firmware to a secure version.