CVE-2024-39789
Multiple external config control vulnerabilities exist in the nas.cgi set_ftp_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists within the `ftp_port` POST parameter.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 1.06%
- CWE
- CWE-15
- Published
- 2025-01-14
- Last modified
- 2026-03-13
Affected products
- Wavlink Wavlink AC3000
Weakness type
Related vulnerabilities
- CVE-2026-85217 — Man-in-the-Middle (MITM) Vulnerability in Autodesk Fusion Desktop
- CVE-2026-19592 — OpenAI Codex CLI for Windows, macOS, and Linux and Codex Desktop for Windows and macOS...
- CVE-2026-19593 — OpenAI Codex Desktop for Windows and macOS automatically inspected Git metadata and working-tree...
- CVE-2026-16708 — IBM Db2 Mirror for i is affected by multiple vulnerabilities
- CVE-2026-19884 — In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control...
- CVE-2026-73661 — FreePBX: Authenticated Framework AUTHTYPE Can Be Restored From a Crafted Backup
- CVE-2026-66065 — Ouroboros: Untrusted project .env can still reach RCE via omitted execution-routing keys (Incomplete fix of CVE-2026-47211)
- CVE-2026-56567 — HCL iControl is affected by multiple security vulnerabilities.