Wavlink AC3000 Command Injection Vulnerability in Routing Configuration

Vulnerability

A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the internet.cgi set_add_routing() function of version M33A8.V5030.210505. This vulnerability allows authenticated users to execute arbitrary commands on the router by sending specially crafted HTTP requests. The issue arises because the application fails to properly sanitize input from several POST parameters, including 'dest', 'netmask', 'gateway', and 'custom_interface', before executing it as a command.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the affected device.

Reproduction

To reproduce this vulnerability, an authenticated user can send a POST request to the 'internet.cgi' script with the 'page' parameter set to 'addrouting'. The 'dest', 'netmask', 'gateway', and 'custom_interface' parameters can be used to inject commands, which will be executed on the router's operating system.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.3
remediation
0.0
relevance
0.0
threat
4.9
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.