Vulnerability record · CVE-2024-39363 · published 14 January 2025
CVE-2024-39363: Wavlink AC3000 login.cgi set_lang_CountryCode XSS
Wavlink · Wl Wn533a8 Firmware
A cross-site scripting flaw exists in the set_lang_CountryCode() functionality of login.cgi in Wavlink AC3000 firmware M33A8.V5030.210505. A crafted HTTP request can inject script that discloses sensitive information. The record does not specify the exact affected version range beyond the firmware string given.
Description
A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L
Automated analysis
medium priorityCVSS 6.1 medium with user interaction required, but high EPSS and public exploit references raise the practical risk.
What it is
A cross-site scripting flaw exists in the set_lang_CountryCode() functionality of login.cgi in Wavlink AC3000 firmware M33A8.V5030.210505. A crafted HTTP request can inject script that discloses sensitive information. The record does not specify the exact affected version range beyond the firmware string given.
Impact
An attacker can execute script in a victim's browser context, potentially disclosing sensitive information such as session data or credentials. The CVSS vector rates confidentiality and availability impact as low.
Attack surface
Reachable over the network via HTTP to login.cgi; no authentication is required to send the request, but the CVSS vector requires user interaction (UI:R), meaning a victim must be induced to trigger the crafted request.
Exploitation
Not listed in CISA KEV and no ransomware usage documented. EPSS is high at 0.48086 (98.8th percentile), and both references are tagged Exploit, indicating public exploit detail exists.
What to do
- Apply the vendor firmware update for Wavlink AC3000 once available; check Wavlink advisories for the fixed build.
- Restrict management interface access to trusted networks and disable remote WAN administration if not needed.
- Deploy a WAF or input filtering to block script payloads targeting login.cgi parameters.
- Educate users not to follow untrusted links to the device login page.
- Monitor Wavlink advisories for a patched firmware release since the record does not name one.
Detection
- Inspect HTTP requests to login.cgi for script tags or encoded script in the set_lang_CountryCode parameter.
- Alert on anomalous or malformed language/country code values in login.cgi traffic.
- Review web logs for reflected payloads returning to clients from login.cgi.
- Correlate outbound connections from the device after suspicious login.cgi requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://talosintelligence.com/vulnerability_reports/TALOS-2024-2017 | ExploitThird Party Advisory |
| https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-2017 | ExploitThird Party Advisory |
Track CVE-2024-39363 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-39363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.