CVE-2024-39793

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 15

Summary

CVE-2024-39793 is a vulnerability affecting the Wavlink AC3000 M33A8's nas.cgi set_nas functionality in Proftpd. Multiple external configuration control issues have been identified, allowing a specially crafted HTTP request to bypass permissions. An attacker can leverage this vulnerability to make authenticated HTTP requests and exploit the configuration injection flaw present in the `ftp_name` POST parameter. This can potentially lead to unintended changes or unauthorized access to system configurations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share