Multiple directory traversal vulnerabilities exist in the nas.cgi add_dir() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to permission bypass. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A directory traversal vulnerability exists within the `disk_part` POST parameter.

U.S. Cyber Command


The official website for the U.S. Cyber Command. As the nation's first line of defense in cyberspace, we operate at the speed, relevance, and scale necessary to win.

Listed: