ZeroHour

CVE-2024-21797

PoC ×2moderate

Authenticated command injection in Wavlink WL-WN533A8 router TR-069 handler

CVSS 3.1
7.2 high
EPSS
21%p97
Published
()
Modified
AI analysis

CVE-2024-21797 is a command-injection flaw (CWE-74) in the set_TR069() function of adm.cgi on Wavlink AC3000 (WL-WN533A8) firmware M33A8.V5030.210505, where TR-069 settings submitted over HTTP are not properly neutralized before being executed by the device. An attacker triggers it with a specially crafted, authenticated HTTP request to the router's administrative web interface; the CVSS vector (AV:N/AC:L/PR:H) confirms network reachability but requires high-privilege (admin) credentials. Successful exploitation yields arbitrary command execution with high impact on confidentiality, integrity and availability, effectively giving the attacker control of the router and the traffic passing through it. Only Wavlink WL-WN533A8 (AC3000) routers running the affected firmware are implicated by the advisory, and risk is highest for units with the admin interface exposed or with default/shared credentials. No exploitation is confirmed in the wild (not in CISA KEV), but Cisco Talos published a public advisory with proof-of-concept details (TALOS-2024-2028), and the 20.8% EPSS score (97th percentile) indicates an elevated likelihood of exploitation attempts within 30 days.

What to do: Check your router's firmware version and, if it matches or predates M33A8.V5030.210505, upgrade to a newer Wavlink release per Talos advisory TALOS-2024-2028 (no specific fixed version was published in the data). Until patched, keep the admin interface off the WAN side, use a strong unique administrator password, and rotate admin credentials if they are shared, since exploitation requires authenticated administrative access.

Affected
Wavlink WL-WN533A8 (AC3000) router firmware, adm.cgi set_TR069 functionalityM33A8.V5030.210505 (version confirmed by Talos advisory TALOS-2024-2028; exact affected and fixed version ranges not published)
Estimated exposure
moderateroughly 1,000–10,000 internet-exposed devices (single consumer router model, clearly an estimate) — Basis is deployment-pattern reasoning: this is one specific SKU of a budget consumer router brand, so its installed base is far smaller than Wavlink's overall footprint and only a fraction of units are administered over the internet; no…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vendors
wavlink
Products
wl-wn533a8 firmware
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news