CVE-2024-39280
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 15
Summary
CVE-2024-39280 is a newly discovered vulnerability affecting the nas.cgi set_smb_cfg() functionality in Wavlink AC3000 M33A8.V5030.210505. This external configuration control issue permits an authenticated attacker to execute arbitrary commands by sending a specially crafted HTTP request. Successful exploitation of this vulnerability can lead to significant security risks, including unauthorized system access and data breaches. It is essential for users of the affected device to apply the necessary patches as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.