📦 Wl Wn533a8 Firmware

by Wavlink

🔍 What is Wl Wn533a8 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-39800

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by exploiting configuration injection in the openvpn.cgi interface. Attackers can gain full sy...

CVE-2024-39802

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on Wavlink AC3000 routers by sending specially crafted HTTP requests that trigger buffer overflows in the QoS settings funct...

CVE-2024-39788

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to bypass permissions and inject malicious configuration into the FTP settings of Wavlink AC3000 routers. Attackers can manipulate the ftp_name parame...

CVE-2024-39790

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to bypass permissions and inject configuration parameters in Wavlink AC3000 routers. Attackers can manipulate FTP session limits and other settings th...

CVE-2024-39794

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to bypass permissions and inject configuration commands via the ftp_port parameter in Wavlink AC3000 routers. Attackers can manipulate FTP server sett...

CVE-2024-39798

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by exploiting configuration injection in the OpenVPN setup functionality. Attackers can gain f...

CVE-2024-39782

CRITICAL CVSS 9.1 Jan 14, 2025

This CVE describes multiple OS command injection vulnerabilities in the Wavlink AC3000 router's web interface. Authenticated attackers can execute arbitrary commands on the device by sending specially...

CVE-2024-39784

CRITICAL CVSS 9.1 Jan 14, 2025

This CVE describes multiple command injection vulnerabilities in the Wavlink AC3000 router's nas.cgi add_dir() functionality. An authenticated attacker can send specially crafted HTTP requests to exec...

CVE-2024-39786

CRITICAL CVSS 9.1 Jan 14, 2025

This directory traversal vulnerability in Wavlink AC3000 routers allows authenticated attackers to bypass file permissions and access restricted directories. Attackers can exploit the 'adddir_name' PO...

CVE-2024-39768

CRITICAL CVSS 9.1 Jan 14, 2025

This CVE describes multiple buffer overflow vulnerabilities in the Wavlink AC3000 router's internet.cgi set_qos() function. An authenticated attacker can send specially crafted HTTP requests to trigge...

CVE-2024-39770

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on Wavlink AC3000 routers by sending specially crafted HTTP requests that trigger buffer overflows in the QoS configuration ...

CVE-2024-39774

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary code on Wavlink AC3000 routers by sending a specially crafted HTTP request that triggers a stack-based buffer overflow. Attackers...

CVE-2024-39760

CRITICAL CVSS 10.0 Jan 14, 2025

This critical vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on Wavlink AC3000 routers by sending specially crafted HTTP requests to the login.cgi endpoi...

CVE-2024-39762

CRITICAL CVSS 9.1 Jan 14, 2025

This CVE describes multiple OS command injection vulnerabilities in the Wavlink AC3000 router's internet.cgi functionality. An authenticated attacker can send specially crafted HTTP requests to execut...

CVE-2024-39764

CRITICAL CVSS 9.1 Jan 14, 2025

This CVE describes multiple OS command injection vulnerabilities in Wavlink AC3000 routers that allow authenticated attackers to execute arbitrary commands via specially crafted HTTP requests. The vul...

CVE-2024-39604

CRITICAL CVSS 9.0 Jan 14, 2025

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink AC3000 routers by sending specially crafted HTTP requests. Attackers can exploit this via man-in-the-middle attacks ...

CVE-2024-39754

CRITICAL CVSS 10.0 Jan 14, 2025

A critical static login vulnerability in Wavlink AC3000 routers allows unauthenticated remote attackers to gain root access by sending specially crafted network packets. This affects all users of the ...

CVE-2024-39757

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary commands on Wavlink AC3000 routers by exploiting a stack-based buffer overflow in the wireless.cgi AddMac() function. Attackers c...

CVE-2024-39358

CRITICAL CVSS 9.1 Jan 14, 2025

A buffer overflow vulnerability in the Wavlink AC3000 router's adm.cgi set_wzap() function allows authenticated attackers to execute arbitrary code via specially crafted HTTP requests. This affects Wa...

CVE-2024-39360

CRITICAL CVSS 9.1 Jan 14, 2025

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Wavlink AC3000 routers through the nas.cgi interface. Attackers can achieve full system compromise b...

CVE-2022-48164

HIGH CVSS 7.5 Feb 6, 2023

This vulnerability allows unauthenticated attackers to access the ExportLogs.sh script on Wavlink WL-WN533A8 routers, enabling them to download configuration files and log data containing admin creden...