Buffer Overflow Vulnerabilities in Wavlink AC3000 Product by Wavlink
CVE-2024-39769
9.1CRITICAL
What is CVE-2024-39769?
Multiple buffer overflow vulnerabilities have been identified in the internet.cgi set_qos() functionality of the Wavlink AC3000 M33A8.V5030.210505. These vulnerabilities arise when a specially crafted HTTP request is sent to the affected device, leading to stack-based buffer overflows. An authenticated attacker could exploit the cli_mac
POST parameter to trigger these vulnerabilities, potentially compromising the integrity of the device's operation.
Affected Version(s)
Wavlink AC3000 M33A8.V5030.210505