ZeroHour

CVE-2024-37186

PoC ×2moderate

Authenticated OS command injection in Wavlink AC3000 (WN533A8) router

CVSS 3.1
7.2 high
EPSS
23%p98
Published
()
Modified
AI analysis

CVE-2024-37186 is an OS command injection flaw (CWE-77) in the set_ledonoff() function of the adm.cgi endpoint in Wavlink AC3000 (model WL-WN533A8) firmware M33A8.V5030.210505, reported by Cisco Talos. An authenticated attacker sends a specially crafted HTTP request to the LED on/off control, and unsanitized input is passed to the operating system, resulting in arbitrary command execution. Successful exploitation yields full code execution on the router, which an attacker can use to control the device, intercept traffic, or pivot into the local network. Only deployments running the affected Wavlink WN533A8/AC3000 firmware are affected, and the CVSS vector's PR:H metric indicates administrative-level credentials are required to trigger the flaw. There is no confirmed in-the-wild exploitation and the CVE is not in CISA KEV, but a public Talos advisory with proof-of-concept details exists and EPSS assigns a high 22.8% probability of exploitation within 30 days.

What to do: Check Wavlink's support channels and the Talos advisory (TALOS-2024-2032) for a corrected firmware release for the WN533A8 and update as soon as one is published, since no fixed version is specified in the available data. Until patched, avoid exposing the router's admin interface to the internet, use strong and non-default admin credentials, and restrict which clients can reach adm.cgi. Monitor the device for suspicious processes or outbound connections, as exploitation grants arbitrary code execution.

Affected
wavlink WL-WN533A8 (AC3000) firmwareM33A8.V5030.210505 (confirmed affected; no fixed version specified in available data)
Estimated exposure
moderate≈10,000–100,000 devices (estimate) — Wavlink is a budget consumer/SOHO router brand and the WN533A8 is a single model in its lineup, so public internet scans of Wavlink admin panels and typical deployment patterns suggest exposed/installed units in the low tens of thousands,…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vendors
wavlink
Products
wl-wn533a8 firmware
Weakness
CWE-77
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news