Wavlink AC3000 Directory Traversal Vulnerabilities in nas.cgi add_dir() Function

Vulnerability

Multiple directory traversal vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() functionality, version M33A8.V5030.210505. These vulnerabilities allow for permission bypass by exploiting the adddir_name and disk_part POST parameters. An authenticated user can send a crafted HTTP request that takes advantage of improper input validation, leading to unauthorized modification of file or directory permissions on the device.

Impact

Exploitation of these vulnerabilities allows authenticated users to bypass permission restrictions and modify the permissions of any file or directory on the system to read, write, and execute. This could lead to unauthorized access or execution of files, particularly in conjunction with other vulnerabilities or functionalities of the device.

Reproduction

To reproduce this vulnerability, an authenticated user must send a POST request to the nas.cgi page with the adddir_name or disk_part parameters. The request must include a relative path with multiple '../' sequences to traverse directories and reach the desired file or directory. Once the request is sent, the specified file or directory will have its permissions changed to read, write, and execute.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.1
remediation
0.0
relevance
0.0
threat
1.6
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.