Command Injection Vulnerabilities in Wavlink AC3000 M33A8 Router
CVE-2024-39762
9.1CRITICAL
What is CVE-2024-39762?
Multiple OS command injection vulnerabilities have been identified in the internet.cgi set_add_routing() functionality of the Wavlink AC3000 M33A8 router. Through a specially crafted HTTP request, an attacker can exploit these vulnerabilities to execute arbitrary commands. The vulnerabilities are triggered when the netmask
POST parameter is improperly handled, allowing authenticated users to carry out unauthorized command executions.