CVE-2024-39770

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 120

Summary

CVE-2024-39770 is a recently disclosed vulnerability affecting the set_qos() functionality in the internet.cgi component of Wavlink AC3000 M33A8. A maliciously crafted HTTP request can cause stack-based buffer overflows in this feature. Upon successful exploitation, an attacker can gain unauthorized control over the affected system. The vulnerability is located in the en_enable POST parameter, and requires authenticated access to the target device.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share