CVE-2024-34544
Published: 14 January 2025
Description
A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Security Summary
CVE-2024-34544 is a command injection vulnerability in the wireless.cgi AddMac() functionality of the Wavlink AC3000 router running firmware version M33A8.V5030.210505. The flaw allows a specially crafted HTTP request to trigger arbitrary command execution on the device.
An authenticated remote attacker with high privileges can exploit this vulnerability over the network with low complexity and no user interaction required. Successful exploitation grants high-impact confidentiality, integrity, and availability effects across the system's scope, as reflected in its CVSS v3.1 base score of 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). This enables full arbitrary command execution on the targeted router.
Details on mitigation, including any patches or workarounds, are available in the Cisco Talos Intelligence advisory at https://talosintelligence.com/vulnerability_reports/TALOS-2024-2044.
Details
- CWE(s)