CVE-2024-37186
PoC ×2moderateAuthenticated OS command injection in Wavlink AC3000 (WN533A8) router
CVE-2024-37186 is an OS command injection flaw (CWE-77) in the set_ledonoff() function of the adm.cgi endpoint in Wavlink AC3000 (model WL-WN533A8) firmware M33A8.V5030.210505, reported by Cisco Talos. An authenticated attacker sends a specially crafted HTTP request to the LED on/off control, and unsanitized input is passed to the operating system, resulting in arbitrary command execution. Successful exploitation yields full code execution on the router, which an attacker can use to control the device, intercept traffic, or pivot into the local network. Only deployments running the affected Wavlink WN533A8/AC3000 firmware are affected, and the CVSS vector's PR:H metric indicates administrative-level credentials are required to trigger the flaw. There is no confirmed in-the-wild exploitation and the CVE is not in CISA KEV, but a public Talos advisory with proof-of-concept details exists and EPSS assigns a high 22.8% probability of exploitation within 30 days.
What to do: Check Wavlink's support channels and the Talos advisory (TALOS-2024-2032) for a corrected firmware release for the WN533A8 and update as soon as one is published, since no fixed version is specified in the available data. Until patched, avoid exposing the router's admin interface to the internet, use strong and non-default admin credentials, and restrict which clients can reach adm.cgi. Monitor the device for suspicious processes or outbound connections, as exploitation grants arbitrary code execution.
| wavlink WL-WN533A8 (AC3000) firmware | M33A8.V5030.210505 (confirmed affected; no fixed version specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- Vendors
- wavlink
- Products
- wl-wn533a8 firmware
- Weakness
- CWE-77
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H