CVE-2024-39774

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 120

Summary

CVE-2024-39774 is a buffer overflow vulnerability affecting the set_sys_adm() functionality in the adm.cgi file of Wavlink AC3000 M33A8.V5030.210505. This issue arises from insufficient bounds checking on user input, resulting in a stack-based buffer overflow. A maliciously crafted HTTP request can exploit this vulnerability and allow an authenticated attacker to execute arbitrary code or cause the device to crash, potentially leading to serious consequences.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share