Vulnerability Details CVE-2024-21797
                A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
                
                    Exploit prediction scoring system (EPSS) score
                    
                        
                            EPSS Score 0.015
                        
                    
                    
                        
                            EPSS Ranking 80.1%
                        
                    
                 
                
                    CVSS Severity
                    
                        
                            CVSS v3 Score 9.1
                        
                    
                    
                 
                
                
                
                    
                
                
                    
                        Products affected by CVE-2024-21797
                        
                            
                                
                                - 
                                    
                                    
                                        
                                            cpe:2.3:h:wavlink:wl-wn533a8:-
                                         
 
- 
                                    
                                    
                                        
                                            cpe:2.3:o:wavlink:wl-wn533a8_firmware:m33a8.v5030.210505