CVE Feed

    Dashboard / CVE / CVE-2024-48705

    CVE-2024-48705

    Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" function of the "adm.cgi" binary, and is due to improper santization of the user provided "newpass" field

    Published:Sep 2, 2025
    Last Modified:Sep 4, 2025
    EPS:Sep 2, 2025
    EPSS Score:0.08945
    CVSS Score:6.5

    Affected Products

    Vendor
    Wavlink
    Product
    Wl-wn531p3
    Vendor
    Wavlink
    Product
    Wl-wn531p3 Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High