CVE-2024-39363
PoC ×2largeUnauthenticated XSS in Wavlink AC3000 (WL-WN533A8) router login.cgi
CVE-2024-39363 is a cross-site scripting flaw (CWE-80) in the set_lang_CountryCode() function of login.cgi on the Wavlink AC3000 mesh system, confirmed on firmware M33A8.V5030.210505. Because the endpoint does not require authentication, any attacker who can reach the router's web interface can send a specially crafted HTTP request that injects script content into a rendered page. A successful attack can lead to disclosure of sensitive information from the victim's browser session or the administrative interface, consistent with the medium CVSS 6.1 score that reflects low confidentiality and availability impact across scope boundaries. Only Wavlink WL-WN533A8 (AC3000) devices running the identified firmware are confirmed affected. The flaw is documented with a public advisory by Cisco Talos (TALOS-2024-2017), is not yet in CISA's KEV catalog, but carries a high EPSS score of ~48%, indicating elevated odds of exploitation in the next 30 days.
What to do: Check WL-WN533A8 units for firmware M33A8.V5030.210505 and apply the updated Wavlink firmware when the vendor publishes a fix (no fixed version is specified in the advisory data). Until then, restrict the router's web management interface to trusted LAN/VLAN access and avoid exposing login.cgi to the internet, since exploitation requires no credentials. Watch the Talos advisory (TALOS-2024-2017) for patched-release details, and treat the high EPSS (~48%) as reason to prioritize remediation on internet-facing units.
| Wavlink WL-WN533A8 (AC3000) firmware | M33A8.V5030.210505 (confirmed affected; no fixed version specified in available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
- Vendors
- wavlink
- Products
- wl-wn533a8 firmware
- Weakness
- CWE-80
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L