Search: "wavlink"

207 CVEs found

CVE-2024-39363
9.6 CRITICAL

A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure ...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39367
9.1 CRITICAL

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39370
9.1 CRITICAL

An arbitrary code execution vulnerability exists in the adm.cgi set_MeshAp() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. ...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39602
9.1 CRITICAL

An external config control vulnerability exists in the nas.cgi set_nas() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. A...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39603
9.1 CRITICAL

A stack-based buffer overflow vulnerability exists in the wireless.cgi set_wifi_basic_mesh() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary ...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39604
9.0 CRITICAL

A command execution vulnerability exists in the update_filter_url.sh functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An at...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39608
10.0 CRITICAL

A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39754
10.0 CRITICAL

A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can lead to root access. An attacker can send packets t...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39756
9.1 CRITICAL

A buffer overflow vulnerability exists in the adm.cgi rep_as_router() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An a...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39757
9.1 CRITICAL

A stack-based buffer overflow vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execu...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39759
10.0 CRITICAL

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code exec...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39760
10.0 CRITICAL

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code exec...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39761
10.0 CRITICAL

Multiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code exec...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39762
9.1 CRITICAL

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary com...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39763
9.1 CRITICAL

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary com...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39764
9.1 CRITICAL

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary com...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39765
9.1 CRITICAL

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary com...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39768
9.1 CRITICAL

Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflo...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39769
9.1 CRITICAL

Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflo...

Published: 2025-01-14
Products: 2
Vendors:
wavlink
CVE-2024-39770
9.1 CRITICAL

Multiple buffer overflow vulnerabilities exist in the internet.cgi set_qos() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflo...

Published: 2025-01-14
Products: 2
Vendors:
wavlink