CVE-2024-39769

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 120

Summary

CVE-2024-39769 is a buffer overflow vulnerability affecting the set_qos() functionality in Wavlink AC3000 M33A8's internet.cgi file. A maliciously crafted HTTP request can exploit this issue, leading to stack-based buffer overflow. The vulnerability is located in the `cli_mac` POST parameter, and an authenticated user can trigger it. Attackers can potentially execute arbitrary code or cause a denial-of-service condition.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share