Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the sel_open_interface
POST parameter.
One or more system settings or configuration elements can be externally controlled by a user.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wl-wn533a8_firmware | Wavlink | m33a8.v5030.210505 (including) | m33a8.v5030.210505 (including) |