CVE-2024-39762

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 77

Summary

CVE-2024-39762 refers to multiple command injection vulnerabilities discovered in the set_add_routing() functionality of the Wavlink AC3000 M33A8's internet.cgi. This issue can be exploited through a specially crafted HTTP request, allowing an authenticated attacker to execute arbitrary commands. One specific vulnerability is located in the `netmask` POST parameter. These vulnerabilities pose a significant risk, as they allow an attacker to gain unauthorized control over the affected device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share