ZeroHour

CVE-2024-39363

PoC ×2large

Unauthenticated XSS in Wavlink AC3000 (WL-WN533A8) router login.cgi

CVSS 3.1
6.1 medium
EPSS
48%p99
Published
()
Modified
AI analysis

CVE-2024-39363 is a cross-site scripting flaw (CWE-80) in the set_lang_CountryCode() function of login.cgi on the Wavlink AC3000 mesh system, confirmed on firmware M33A8.V5030.210505. Because the endpoint does not require authentication, any attacker who can reach the router's web interface can send a specially crafted HTTP request that injects script content into a rendered page. A successful attack can lead to disclosure of sensitive information from the victim's browser session or the administrative interface, consistent with the medium CVSS 6.1 score that reflects low confidentiality and availability impact across scope boundaries. Only Wavlink WL-WN533A8 (AC3000) devices running the identified firmware are confirmed affected. The flaw is documented with a public advisory by Cisco Talos (TALOS-2024-2017), is not yet in CISA's KEV catalog, but carries a high EPSS score of ~48%, indicating elevated odds of exploitation in the next 30 days.

What to do: Check WL-WN533A8 units for firmware M33A8.V5030.210505 and apply the updated Wavlink firmware when the vendor publishes a fix (no fixed version is specified in the advisory data). Until then, restrict the router's web management interface to trusted LAN/VLAN access and avoid exposing login.cgi to the internet, since exploitation requires no credentials. Watch the Talos advisory (TALOS-2024-2017) for patched-release details, and treat the high EPSS (~48%) as reason to prioritize remediation on internet-facing units.

Affected
Wavlink WL-WN533A8 (AC3000) firmwareM33A8.V5030.210505 (confirmed affected; no fixed version specified in available data)
Estimated exposure
largeroughly 10,000–50,000 internet-exposed routers (estimate from public scan data on exposed Wavlink web interfaces; consumer install base larger) — Wavlink is a budget consumer/SOHO mesh-router brand, and public internet-wide scans of exposed Wavlink login/admin pages typically show on the order of tens of thousands of reachable devices, while total units deployed behind NAT are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

Vendors
wavlink
Products
wl-wn533a8 firmware
Weakness
CWE-80
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L

In the news