Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to stack-based buffer overflow. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A buffer overflow vulnerability exists in the `sel_mode` POST parameter.
2025-01-14T15:15:25.840
2025-11-03T22:17:10.703
Modified
CVSSv3.1: 9.1 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | wavlink | wl-wn533a8_firmware | m33a8.v5030.210505 | Yes |
| Hardware | wavlink | wl-wn533a8 | - | No |