CVE-2024-39793
CVSS 3.1 Score 9.1 of 10 (high)
Details
Published Jan 14, 2025
CWE ID 15
Summary
CVE-2024-39793 is a vulnerability affecting the Wavlink AC3000 M33A8's nas.cgi set_nas functionality in Proftpd. Multiple external configuration control issues have been identified, allowing a specially crafted HTTP request to bypass permissions. An attacker can leverage this vulnerability to make authenticated HTTP requests and exploit the configuration injection flaw present in the `ftp_name` POST parameter. This can potentially lead to unintended changes or unauthorized access to system configurations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.