PT-2024-25369 · Levelone · Levelone Wbr-6012

Patrick Desantis

·

Published

2024-10-30

·

Updated

2024-11-13

·

CVE-2024-33603

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LevelOne WBR-6012 router (affected versions not specified)
Description The router has an information disclosure issue in its web application, allowing unauthenticated users to access a verbose system log page. This exposes sensitive data, including memory addresses and IP addresses for login attempts, which could lead to session hijacking due to the device's reliance on IP address for authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-33603

Affected Products

Levelone Wbr-6012