Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A configuration injection vulnerability exists in the `ftp_port` POST parameter.
2025-01-14T15:15:24.663
2025-11-03T22:17:09.867
Modified
CVSSv3.1: 9.1 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | wavlink | wl-wn533a8_firmware | m33a8.v5030.210505 | Yes |
| Hardware | wavlink | wl-wn533a8 | - | No |