ZeroHour

CVE-2024-39280

PoC ×2niche

Authenticated command injection in Wavlink AC3000 (WL-WN533A8) SMB config

CVSS 3.1
9.1 critical
EPSS
34%p98
Published
()
Modified
AI analysis

CVE-2024-39280 is an external config control flaw in the set_smb_cfg() handler of nas.cgi on Wavlink AC3000 (WL-WN533A8) routers, in which attacker-controlled SMB configuration values are passed directly to command execution. It is triggered by a specially crafted, authenticated HTTP request, meaning an attacker needs valid (typically administrator) credentials on the router's web interface. Successful exploitation yields arbitrary command execution on the device, giving an attacker full control of the router and the ability to intercept or alter traffic on networks it serves. Only Wavlink WL-WN533A8 (AC3000) units running the firmware version referenced in the advisory, M33A8.V5030.210505, are confirmed affected. The flaw was disclosed by Cisco Talos (TALOS-2024-2055) with a public proof-of-concept; it is not in CISA's KEV, and EPSS assigns roughly a 34% probability of exploitation within 30 days, indicating elevated risk but no confirmed in-the-wild exploitation.

What to do: Upgrade affected WN533A8 units to the newest firmware available from Wavlink and confirm the fixed version with the vendor, since no fixed release is named in the data. Until patched, do not expose the router's admin web interface to the public internet and ensure the admin account does not use default credentials, because exploitation requires an authenticated request. Check the installed firmware build (look for M33A8.V5030.210505) and monitor for additional Wavlink advisories, as Talos disclosed a batch of related Wavlink flaws.

Affected
Wavlink WL-WN533A8 (AC3000) firmwareM33A8.V5030.210505 (version confirmed in the advisory)
Estimated exposure
nichelikely on the order of thousands of deployed consumer units (no public install counts for this single model) — No public install or internet-exposed device counts exist for the Wavlink WL-WN533A8, so the estimate is an order-of-magnitude guess based on it being a single budget consumer mesh router model, of which only a fraction typically have…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

Vendors
wavlink
Products
wl-wn533a8 firmware
Weakness
CWE-15
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news