External Configuration Control Flaw in Wavlink AC3000 Product
CVE-2024-38666

9.1CRITICAL

Key Information:

Vendor

Wavlink

Vendor
CVE Published:
14 January 2025

What is CVE-2024-38666?

An external configuration control vulnerability in the openvpn.cgi component of Wavlink AC3000 M33A8 allows attackers to exploit the openvpn_client_setup() function through a specially crafted HTTP request. This could lead to arbitrary command execution if an authenticated HTTP request is made, posing significant security risks to affected systems.

Affected Version(s)

Wavlink AC3000 M33A8.V5030.210505

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

Credit

Discovered by Lilith >_> of Cisco Talos.
.
CVE-2024-38666 : External Configuration Control Flaw in Wavlink AC3000 Product