A firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary firmware update. An attacker can send an unauthenticated message to trigger this vulnerability.
2025-01-14T15:15:20.433
2025-08-21T20:38:20.400
Analyzed
CVSSv3.1: 10.0 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | wavlink | wl-wn533a8_firmware | m33a8.v5030.210505 | Yes |
| Hardware | wavlink | wl-wn533a8 | - | No |