OS Command Injection in Wavlink AC3000 M33A8 Router
CVE-2024-39761
10CRITICAL
What is CVE-2024-39761?
The Wavlink AC3000 M33A8 router is exposed to multiple OS command injection vulnerabilities that can be exploited through its login.cgi set_sys_init() functionality. Attackers can craft specific HTTP requests that exploit these vulnerabilities, allowing them to execute arbitrary code on affected systems. One significant vector involves the restart_week_value
POST parameter, which can lead to unauthorized control over the router. This vulnerability emphasizes the need for securing network devices against injection attacks and reviewing configurations to prevent exploitation.