CVE-2024-39760
CVSS 3.1 Score 10 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 77
Summary
CVE-2024-39760 is a critical vulnerability affecting the login.cgi set_sys_init() functionality of the Wavlink AC3000 M33A8 V5030.210505 firmware. Multiple OS command injection flaws have been identified, which can be triggered by a specially crafted HTTP request. An attacker need not be authenticated to exploit these vulnerabilities. Additionally, a command injection vulnerability has been discovered within the `restart_min_value` POST parameter. These vulnerabilities could potentially allow an attacker to execute arbitrary code on the affected system.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.