CVE-2024-39363

CVSS 3.1 Score 9.6 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 80

Summary

CVE-2024-39363 is a newly disclosed cross-site scripting (XSS) vulnerability affecting the set_lang_CountryCode() functionality in the login.cgi of Wavlink AC3000 M33A8 V5030.210505. This issue allows an attacker to craft a malicious HTTP request, which, when received by the affected device, can lead to the disclosure of sensitive information. The attack can be executed without authentication, posing a significant risk to users who access the vulnerable login page. Organizations using the Wavlink AC3000 M33A8 V5030.210505 are urged to apply the necessary patches or updates as soon as possible to mitigate this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share