PT-2024-25222 · Lb Link · Lb-Link Bl-W1210M
Published
2024-06-13
·
Updated
2025-05-30
·
CVE-2024-33375
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LB-LINK BL-W1210M version 2.0
Description
The issue concerns the storage of user credentials in plaintext within the router's firmware. This means that user credentials, such as usernames and passwords, are stored in an unencrypted format, making them easily accessible to unauthorized parties.
Recommendations
For LB-LINK BL-W1210M version 2.0, consider changing the default administrator credentials and any other passwords stored on the device to minimize potential risks. As a temporary workaround, restrict access to the router's firmware and configuration interface to prevent unauthorized access to the stored credentials. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lb-Link Bl-W1210M