CVE-2024-21797
published 2025-01-14CVE-2024-21797: A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can…
PriorityP358high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
20.77%
97.2th percentile
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| wavlink | wavlink_ac3000 | — | — |
| wavlink | wl-wn533a8_firmware | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_oracle9.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hpf7-2hg3-3g3h: A command execution vulnerability exists in the adm
ghsa_unreviewed·2025-01-14
CVE-2024-21797 [CRITICAL] CWE-74 GHSA-hpf7-2hg3-3g3h: A command execution vulnerability exists in the adm
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Oracle
Oracle Oracle Analytics Risk Matrix: Pipeline Test Failures (Joblib) — CVE-2022-21797
vendor_oracle·2024-07-15·CVSS 9.8
CVE-2022-21797 [HIGH] Oracle Oracle Analytics Risk Matrix: Pipeline Test Failures (Joblib) — CVE-2022-21797
Oracle Oracle Analytics Risk Matrix: Pipeline Test Failures (Joblib) vulnerability
CVE: CVE-2022-21797
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
No detection rules found.
No public exploits indexed.
Talos
Slew of WavLink vulnerabilities
blogs_talos·2025-01-15·CVSS 8.0
[HIGH] Slew of WavLink vulnerabilities
## Slew of WavLink vulnerabilities
Lilith >_> of Cisco Talos discovered these vulnerabilities.
Forty-four vulnerabilities and sixty-three CVEs were discovered across ten .cgi and three .sh files, as well as the static login page, of the Wavlink AC3000 wireless router web application.
The Wavlink AC3000 wireless router is one of the most popular gigabit routers in the US, in part due to both its potential speed capabilities and low price point.
Talos is releasing these advisories in accordance with Cisco’s third-party vulnerability disclosure policy . Wavlink has declined to release a patch for these vulnerabilities.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org , and our latest Vulnerability Advisories are al
Talos
Slew of WavLink vulnerabilities
blogs_talos·2025-01-15·CVSS 8.0
[HIGH] Slew of WavLink vulnerabilities
Lilith >_> of Cisco Talos discovered these vulnerabilities.
Forty-four vulnerabilities and sixty-three CVEs were discovered across ten .cgi and three .sh files, as well as the static login page, of the Wavlink AC3000 wireless router web application.
The Wavlink AC3000 wireless router is one of the most popular gigabit routers in the US, in part due to both its potential speed capabilities and low price point.
Talos is releasing these advisories in accordance with Cisco’s third-party vulnerability disclosure policy. Wavlink has declined to release a patch for these vulnerabilities.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s we
2025-01-14
Published