CVE-2024-39280
PoC ×2nicheAuthenticated command injection in Wavlink AC3000 (WL-WN533A8) SMB config
CVE-2024-39280 is an external config control flaw in the set_smb_cfg() handler of nas.cgi on Wavlink AC3000 (WL-WN533A8) routers, in which attacker-controlled SMB configuration values are passed directly to command execution. It is triggered by a specially crafted, authenticated HTTP request, meaning an attacker needs valid (typically administrator) credentials on the router's web interface. Successful exploitation yields arbitrary command execution on the device, giving an attacker full control of the router and the ability to intercept or alter traffic on networks it serves. Only Wavlink WL-WN533A8 (AC3000) units running the firmware version referenced in the advisory, M33A8.V5030.210505, are confirmed affected. The flaw was disclosed by Cisco Talos (TALOS-2024-2055) with a public proof-of-concept; it is not in CISA's KEV, and EPSS assigns roughly a 34% probability of exploitation within 30 days, indicating elevated risk but no confirmed in-the-wild exploitation.
What to do: Upgrade affected WN533A8 units to the newest firmware available from Wavlink and confirm the fixed version with the vendor, since no fixed release is named in the data. Until patched, do not expose the router's admin web interface to the public internet and ensure the admin account does not use default credentials, because exploitation requires an authenticated request. Check the installed firmware build (look for M33A8.V5030.210505) and monitor for additional Wavlink advisories, as Talos disclosed a batch of related Wavlink flaws.
| Wavlink WL-WN533A8 (AC3000) firmware | M33A8.V5030.210505 (version confirmed in the advisory) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An external config control vulnerability exists in the nas.cgi set_smb_cfg() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
- Vendors
- wavlink
- Products
- wl-wn533a8 firmware
- Weakness
- CWE-15
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H