CVE-2024-39800
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2024-39800: Wavlink AC3000 M33A8.V5030.210505 contains multiple external configuration control vulnerabilities in its openvpn.cgi openvpn_server_setup() functionality. A maliciously crafted HTTP request can exploit these vulnerabilities, resulting in arbitrary command execution. Additionally, an injection flaw exists in the `open_port` POST parameter, further increasing the risk for attackers to gain unauthorized access and manipulate OpenVPN server settings. This issue affects authenticated users and requires no prior knowledge or exploitation of other vulnerabilities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.