PT-2025-23523 · Sitecom · Sitecom Wlx-2006
Published
2025-06-02
·
Updated
2025-06-25
·
CVE-2024-40112
CVSS v3.1
5.9
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Sitecom WLX-2006 Wall Mount Range Extender N300 versions 1.5 and before
Description
A Local File Inclusion (LFI) issue exists, which allows an attacker to manipulate the
language cookie to include arbitrary files from the server. This can be exploited to disclose sensitive information.Recommendations
For versions 1.5 and before, consider disabling the manipulation of the
language cookie as a temporary workaround until a patch is available. Restrict access to sensitive files on the server to minimize the risk of exploitation.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sitecom Wlx-2006