Command Injection Vulnerabilities in Wavlink AC3000 M33A8 Router
CVE-2024-39762
9.1CRITICAL
What is CVE-2024-39762?
Multiple OS command injection vulnerabilities have been identified in the internet.cgi set_add_routing() functionality of the Wavlink AC3000 M33A8 router. Through a specially crafted HTTP request, an attacker can exploit these vulnerabilities to execute arbitrary commands. The vulnerabilities are triggered when the netmask POST parameter is improperly handled, allowing authenticated users to carry out unauthorized command executions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Wavlink AC3000 M33A8.V5030.210505
