Wavlink AC3000
cpe:2.3:h:wavlink:jetstream_ac3000:*:*:*:*:*:*:*, +1 more
- M33A8.V5030.210505
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the adm.cgi file within the set_ledonoff() function. This vulnerability allows authenticated attackers to execute arbitrary commands on the device. The issue arises from the way the router's web interface handles HTTP requests, particularly those directed to .cgi scripts.
Exploitation of this vulnerability allows for arbitrary code execution on the affected device.
To reproduce this vulnerability, an authenticated user must send an HTTP POST request to the adm.cgi script with the 'led_cmd' parameter. The request will bypass authentication checks and execute the injected command, leading to command injection on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.