CVE-2024-39608
CVSS 3.1 Score 10 of 10 (high)
Details
Summary
CVE-2024-39608 is a vulnerability affecting the login.cgi functionality of Wavlink AC3000 M33A8 with firmware version V5030.210505. An unauthenticated attacker can exploit this weakness by crafting a malicious HTTP request, triggering an arbitrary firmware update. This vulnerability poses a significant risk as it allows an attacker to potentially gain control over the device's firmware, which could lead to unauthorized access, data theft, or other malicious activities. Organizations and individuals using this device are urged to apply the necessary firmware updates as soon as they become available to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.