Wavlink AC3000 Command Injection Vulnerability in nas.cgi add_dir() Function
Vulnerability
A command injection vulnerability has been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() function. This vulnerability allows authenticated users to execute arbitrary commands on the device by sending a specially crafted HTTP request. The issue arises in the disk_part and adddir_name POST parameters, where injected commands can be executed with system privileges.
Impact
Exploitation of this vulnerability allows for arbitrary command execution on the affected device.
Reproduction
To reproduce this vulnerability, an authenticated user can send a POST request to the nas.cgi add_dir() function. The request must include a command injection payload in either the disk_part or adddir_name parameter. Once the payload is executed, the injected command will be executed on the router's operating system, leading to unauthorized command execution.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
