CVE-2024-36272

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 120

Summary

CVE-2024-36272 is a buffer overflow vulnerability affecting the set_info() functionality in the usbip.cgi component of Wavlink AC3000 M33A8.V5030.210505. This issue arises due to insufficient bounds checking on user input, leading to a stack-based buffer overflow. An attacker can exploit this vulnerability by sending a specially crafted HTTP request, gaining unauthorized control over the affected device. Successful exploitation may result in arbitrary code execution or denial of service.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share