Wavlink AC3000 Directory Traversal Vulnerabilities in nas.cgi add_dir() Function
Vulnerability
Multiple directory traversal vulnerabilities have been identified in the Wavlink AC3000 router, specifically in the nas.cgi add_dir() functionality, version M33A8.V5030.210505. These vulnerabilities allow for permission bypass through specially crafted HTTP requests. The issues arise because the add_dir function does not properly validate input parameters, enabling attackers to manipulate directory paths and change file permissions on the device.
Impact
Exploitation of these vulnerabilities allows authenticated users to bypass permission restrictions and gain unauthorized access to the file system. This could lead to unauthorized modification of files or execution of scripts with elevated privileges.
Reproduction
To reproduce this vulnerability, an authenticated user can send a POST request to the nas.cgi add_dir() function. The request must include the 'adddir_name' or 'disk_part' POST parameters, crafted with relative paths containing directory traversal sequences. Once the request is processed, the specified files or directories will have their permissions changed to read, write, and execute.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
