CVE-2024-39800

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 15

Summary

CVE-2024-39800: Wavlink AC3000 M33A8.V5030.210505 contains multiple external configuration control vulnerabilities in its openvpn.cgi openvpn_server_setup() functionality. A maliciously crafted HTTP request can exploit these vulnerabilities, resulting in arbitrary command execution. Additionally, an injection flaw exists in the `open_port` POST parameter, further increasing the risk for attackers to gain unauthorized access and manipulate OpenVPN server settings. This issue affects authenticated users and requires no prior knowledge or exploitation of other vulnerabilities.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share