CVE-2024-39367
9.1
CRITICAL · CVSS 3.1 · EPSS 8.2% (pctl 95)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 8.25% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-77 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-01-14 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| wavlink | wl-wn533a8 |
| wavlink | wl-wn533a8 firmware |
References
→ the Explorer · watch your stack · NVD