PT-2024-25222 · Lb Link · Lb-Link Bl-W1210M

Published

2024-06-13

·

Updated

2025-05-30

·

CVE-2024-33375

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LB-LINK BL-W1210M version 2.0
Description The issue concerns the storage of user credentials in plaintext within the router's firmware. This means that user credentials, such as usernames and passwords, are stored in an unencrypted format, making them easily accessible to unauthorized parties.
Recommendations For LB-LINK BL-W1210M version 2.0, consider changing the default administrator credentials and any other passwords stored on the device to minimize potential risks. As a temporary workaround, restrict access to the router's firmware and configuration interface to prevent unauthorized access to the stored credentials. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

BDU:2025-07205
CVE-2024-33375

Affected Products

Lb-Link Bl-W1210M