CVE-2024-39794

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 15

Summary

CVE-2024-39794 is a vulnerability affecting the nas.cgi set_nas() function in the Wavlink AC3000 M33A8's ProFTPD implementation. Multiple external configuration control vulnerabilities have been identified, allowing a specially crafted HTTP request to bypass permissions. An attacker can exploit this by making an authenticated HTTP request to trigger the vulnerabilities. Additionally, a configuration injection vulnerability was found in the `ftp_port` POST parameter. These issues could potentially expose the affected system to unauthorized access or data theft.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share