CVE-2024-36258

CVSS 3.1 Score 10 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 121

Summary

CVE-2024-36258 is a newly disclosed vulnerability affecting the touchlist_sync.cgi touchlistsync() function in Wavlink AC3000 M33A8.V5030.210505. This issue involves a stack-based buffer overflow, which can be exploited by an attacker sending a specially crafted HTTP request. Successful exploitation grants arbitrary code execution rights, posing a significant security risk. Users are advised to update their affected devices as soon as a patch becomes available.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share