CVE-2024-39768

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 120

Summary

CVE-2024-39768 is a recently disclosed vulnerability affecting the set_qos() functionality in the internet.cgi component of Wavlink AC3000 M33A8 devices. The issue involves multiple buffer overflow vulnerabilities, which can be triggered by a specially crafted HTTP request. Authenticated users can exploit these vulnerabilities by sending malicious input to the `cli_name` POST parameter. Successful exploitation may result in stack-based buffer overflow and subsequent code execution, potentially leading to unauthorized system access or data theft.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share