Description
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54944 | Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field |
References
| Link | Providers |
|---|---|
| http://wavlink.com |
|
| https://github.com/L41KAA/CVE-2024-48705 |
|
History
Thu, 04 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wavlink
Wavlink wl-wn531p3 Wavlink wl-wn531p3 Firmware |
|
| CPEs | cpe:2.3:h:wavlink:wl-wn531p3:-:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-wn531p3_firmware:m32a3_v1410_230602:*:*:*:*:*:*:* cpe:2.3:o:wavlink:wl-wn531p3_firmware:m32a3_v1410_240222:*:*:*:*:*:*:* |
|
| Vendors & Products |
Wavlink
Wavlink wl-wn531p3 Wavlink wl-wn531p3 Firmware |
Tue, 02 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
cvssV3_1
|
Tue, 02 Sep 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-02T19:35:31.106Z
Reserved: 2024-10-08T00:00:00.000Z
Link: CVE-2024-48705
Updated: 2025-09-02T19:35:26.995Z
Status : Analyzed
Published: 2025-09-02T15:15:31.837
Modified: 2025-09-04T17:47:01.483
Link: CVE-2024-48705
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD