← Vulnerability feed

Vulnerability record · CVE-2024-39363 · published 14 January 2025

CVE-2024-39363: Wavlink AC3000 login.cgi set_lang_CountryCode XSS

Wavlink · Wl Wn533a8 Firmware

A cross-site scripting flaw exists in the set_lang_CountryCode() functionality of login.cgi in Wavlink AC3000 firmware M33A8.V5030.210505. A crafted HTTP request can inject script that discloses sensitive information. The record does not specify the exact affected version range beyond the firmware string given.

6.1 CVSS 3.1 Medium EPSS 48% · top 1.2% CWE-80 · CWE-80
6.1CVSS 3.1 base score
48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A cross-site scripting (xss) vulnerability exists in the login.cgi set_lang_CountryCode() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a disclosure of sensitive information. An attacker can make an unauthenticated HTTP request to trigger this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

medium priorityCVSS 6.1 medium with user interaction required, but high EPSS and public exploit references raise the practical risk.

What it is

A cross-site scripting flaw exists in the set_lang_CountryCode() functionality of login.cgi in Wavlink AC3000 firmware M33A8.V5030.210505. A crafted HTTP request can inject script that discloses sensitive information. The record does not specify the exact affected version range beyond the firmware string given.

Impact

An attacker can execute script in a victim's browser context, potentially disclosing sensitive information such as session data or credentials. The CVSS vector rates confidentiality and availability impact as low.

Attack surface

Reachable over the network via HTTP to login.cgi; no authentication is required to send the request, but the CVSS vector requires user interaction (UI:R), meaning a victim must be induced to trigger the crafted request.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is high at 0.48086 (98.8th percentile), and both references are tagged Exploit, indicating public exploit detail exists.

What to do

  • Apply the vendor firmware update for Wavlink AC3000 once available; check Wavlink advisories for the fixed build.
  • Restrict management interface access to trusted networks and disable remote WAN administration if not needed.
  • Deploy a WAF or input filtering to block script payloads targeting login.cgi parameters.
  • Educate users not to follow untrusted links to the device login page.
  • Monitor Wavlink advisories for a patched firmware release since the record does not name one.

Detection

  • Inspect HTTP requests to login.cgi for script tags or encoded script in the set_lang_CountryCode parameter.
  • Alert on anomalous or malformed language/country code values in login.cgi traffic.
  • Review web logs for reflected payloads returning to clients from login.cgi.
  • Correlate outbound connections from the device after suspicious login.cgi requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-39363 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-39759Wavlink wl-wn533a8 firmware command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…EPSS 8.2%9.8CVE-2024-39760Wavlink wl-wn533a8 firmware command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…EPSS 17%9.8CVE-2024-39761Wavlink wl-wn533a8 firmware command injection vulnerabilityMultiple OS command injection vulnerabilities exist in the login.cgi set_sys_init() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially c…EPSS 8.2%9.8CVE-2024-39608Wavlink wl-wn533a8 firmware missing authentication for critical function vulnerabilityA firmware update vulnerability exists in the login.cgi functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead…EPSS 1.4%9.8CVE-2024-39754Wavlink wl-wn533a8 firmware vulnerabilityA static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets can …EPSS 1.3%9.8CVE-2024-36258Wavlink wl-wn533a8 firmware stack-based buffer overflow vulnerabilityA stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A sp…EPSS 12%9.8CVE-2024-36290Wavlink wl-wn533a8 firmware classic buffer overflow vulnerabilityA buffer overflow vulnerability exists in the login.cgi Goto_chidx() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP req…EPSS 1.4%9.8CVE-2024-34166Wavlink wl-wn533a8 firmware command injection vulnerabilityAn os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A speciall…EPSS 16%

Source: NIST National Vulnerability Database (record CVE-2024-39363), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.