wavlink

210 tracked vulnerabilities.

CVE-2024-39604 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Remote Code Execution via update_filter_url.sh
Jan 14, 2025
CVSS 9.0
EPSS 0.01
CVE-2024-39603 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in wireless.cgi set_wifi_basic_mesh()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39602 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39370 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Remote Code Execution via adm.cgi set_MeshAp()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39367 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via firewall.cgi iptablesWebsFilterRun()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39363 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Cross-Site Scripting in login.cgi set_lang_CountryCode()
Jan 14, 2025
CVSS 9.6
EPSS 0.11
CVE-2024-39360 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via nas.cgi remove_dir()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39359 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in wireless.cgi DeleteMac()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39358 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in adm.cgi set_wzap()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39357 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in wireless.cgi SetName()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39299 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow via qos.cgi qos_sta_settings
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39294 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-based Buffer Overflow in adm.cgi set_wzdgw4G()
Jan 14, 2025
CVSS 9.1
EPSS 0.00
CVE-2024-39288 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow in internet.cgi set_add_routing()
Jan 14, 2025
CVSS 9.1
EPSS 0.15
CVE-2024-39280 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - RCE
Jan 14, 2025
CVSS 9.1
EPSS 0.06
CVE-2024-39273 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Unauthenticated Arbitrary Firmware Update via fw_check.sh
Jan 14, 2025
CVSS 9.0
EPSS 0.00
CVE-2024-38666 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
Jan 14, 2025
CVSS 9.1
EPSS 0.06
CVE-2024-37357 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow in adm.cgi set_TR069()
Jan 14, 2025
CVSS 9.1
EPSS 0.14
CVE-2024-37186 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated OS Command Injection via adm.cgi set_ledonoff()
Jan 14, 2025
CVSS 9.1
EPSS 0.05
CVE-2024-37184 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Authenticated Stack-Based Buffer Overflow via adm.cgi rep_as_bridge()
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-36493 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Buffer Overflow
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-36295 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
Jan 14, 2025
CVSS 9.1
EPSS 0.08
CVE-2024-36290 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Buffer Overflow
Jan 14, 2025
CVSS 10.0
EPSS 0.02
CVE-2024-36272 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Buffer Overflow
Jan 14, 2025
CVSS 9.1
EPSS 0.01
CVE-2024-36258 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Buffer Overflow
Jan 14, 2025
CVSS 10.0
EPSS 0.16
CVE-2024-34544 CRITICAL
Wavlink AC3000 M33A8.V5030.210505 - Command Injection
Jan 14, 2025
CVSS 9.1
EPSS 0.01