CVE-2024-39762
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 77
Summary
CVE-2024-39762 refers to multiple command injection vulnerabilities discovered in the set_add_routing() functionality of the Wavlink AC3000 M33A8's internet.cgi. This issue can be exploited through a specially crafted HTTP request, allowing an authenticated attacker to execute arbitrary commands. One specific vulnerability is located in the `netmask` POST parameter. These vulnerabilities pose a significant risk, as they allow an attacker to gain unauthorized control over the affected device.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.