Security Advisory

CVE-2024-39608

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-01-14 14:21:23
Last updated 2025-01-14 16:04:12
Assigner talos
CVSS score 10.0
State PUBLISHED

Description

A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerability.