CVE-2024-39754
CRITICALDescription
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets to trigger this vulnerability.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| wavlink | wl-wn533a8_firmware |
| wavlink | wl-wn533a8 |
References
Frequently Asked Questions
What is CVE-2024-39754? +
How severe is CVE-2024-39754? +
What products are affected by CVE-2024-39754? +
How do I check if I'm vulnerable to CVE-2024-39754? +
Related Vulnerabilities
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, …
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located …
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 …
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not …
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized …
Delta Electronics AS320T has denial of service via the undocumented subfunction vulnerability.