CVE-2024-36295
PoC ×2nicheAuthenticated Command Injection in Wavlink WL-WN533A8 (AC3000) Router
CVE-2024-36295 is an authenticated command execution flaw in the qos_sta() function of the qos.cgi script on Wavlink AC3000 (model WL-WN533A8) routers running firmware M33A8.V5030.210505. An attacker who already has administrative credentials sends a specially crafted HTTP request to the router's QoS functionality, and the device mishandles the request (CWE-74), allowing attacker-supplied input to run as OS commands. Successful exploitation yields arbitrary command execution on the router itself, giving the attacker control of the device and a foothold in the victim's local network. Only users of the affected Wavlink WL-WN533A8 (AC3000) model with the indicated firmware are affected, and because the flaw requires high-privilege (admin) authentication, exposed WAN-facing admin interfaces are the primary risk. There are no confirmed in-the-wild exploits and the flaw is not in CISA KEV, but Cisco Talos has published a public advisory (TALOS-2024-2047) and the EPSS score of 20.8% (97th percentile) suggests a meaningful chance of exploitation within 30 days.
What to do: Check whether any WL-WN533A8/AC3000 units in your environment run firmware M33A8.V5030.210505 and contact Wavlink for an updated fixed firmware, since no patched version is specified in the available data. Until updated firmware is applied, restrict the router's administrative interface to the LAN (disable WAN/remote administration) and use strong, unique admin credentials, as exploitation requires an authenticated admin HTTP request. Review Talos advisory TALOS-2024-2047 for details, and monitor for updated advisories, as multiple Wavlink vulnerabilities were disclosed in this batch.
| Wavlink WL-WN533A8 (AC3000) router firmware | M33A8.V5030.210505 (the version confirmed vulnerable in the Talos analysis; other firmware versions were not specified in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A command execution vulnerability exists in the qos.cgi qos_sta() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- Vendors
- wavlink
- Products
- wl-wn533a8 firmware
- Weakness
- CWE-74
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H