wavlink

210 tracked vulnerabilities.

CVE-2024-39789 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39788 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Config Injection
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39787 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Path Traversal via disk_part POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39786 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Path Traversal via adddir_name Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39785 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via adddir_name Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39784 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via disk_part POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39783 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via restart_week Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39782 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via adm.cgi sch_reboot() restart_min Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39781 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via adm.cgi sch_reboot() restart_hour Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39774 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow via adm.cgi set_sys_adm()
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-39773 MEDIUM
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Information Disclosure via testsave.sh
Jan 14, 2025
CVSS 5.3
EPSS 0.01
CVE-2024-39770 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow via en_enable POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-39769 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow via cli_mac POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39768 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow via cli_name POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-39765 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via custom_interface POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39764 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via dest POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39763 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via gateway POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39762 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via netmask POST Parameter
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39761 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated OS Command Injection via restart_week_value Parameter
Jan 14, 2025
CVSS 10.0
EPSS 0.01
CVE-2024-39760 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - OS Command Injection via login.cgi restart_min_value
Jan 14, 2025
CVSS 10.0
EPSS 0.01
CVE-2024-39759 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated OS Command Injection via login.cgi restart_hour_value Parameter
Jan 14, 2025
CVSS 10.0
EPSS 0.01
CVE-2024-39757 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in wireless.cgi AddMac()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39756 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow in adm.cgi rep_as_router()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39754 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 10.0
EPSS 0.00
CVE-2024-39608 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via login.cgi
Jan 14, 2025
CVSS 10.0
EPSS 0.00