CVE-2024-21797
PoC ×2moderateAuthenticated command injection in Wavlink WL-WN533A8 router TR-069 handler
CVE-2024-21797 is a command-injection flaw (CWE-74) in the set_TR069() function of adm.cgi on Wavlink AC3000 (WL-WN533A8) firmware M33A8.V5030.210505, where TR-069 settings submitted over HTTP are not properly neutralized before being executed by the device. An attacker triggers it with a specially crafted, authenticated HTTP request to the router's administrative web interface; the CVSS vector (AV:N/AC:L/PR:H) confirms network reachability but requires high-privilege (admin) credentials. Successful exploitation yields arbitrary command execution with high impact on confidentiality, integrity and availability, effectively giving the attacker control of the router and the traffic passing through it. Only Wavlink WL-WN533A8 (AC3000) routers running the affected firmware are implicated by the advisory, and risk is highest for units with the admin interface exposed or with default/shared credentials. No exploitation is confirmed in the wild (not in CISA KEV), but Cisco Talos published a public advisory with proof-of-concept details (TALOS-2024-2028), and the 20.8% EPSS score (97th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.
What to do: Check your router's firmware version and, if it matches or predates M33A8.V5030.210505, upgrade to a newer Wavlink release per Talos advisory TALOS-2024-2028 (no specific fixed version was published in the data). Until patched, keep the admin interface off the WAN side, use a strong unique administrator password, and rotate admin credentials if they are shared, since exploitation requires authenticated administrative access.
| Wavlink WL-WN533A8 (AC3000) router firmware, adm.cgi set_TR069 functionality | M33A8.V5030.210505 (version confirmed by Talos advisory TALOS-2024-2028; exact affected and fixed version ranges not published) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- Vendors
- wavlink
- Products
- wl-wn533a8 firmware
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H