CVE-2024-39367: An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A...

9.1 CVSS

Description

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Classification

CVE ID: CVE-2024-39367

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.1

Affected Products

Vendor: Wavlink

Product: Wavlink AC3000

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-12 (when was this score calculated)

References

https://talosintelligence.com/vulnerability_reports/TALOS-2024-2023

Timeline