CVE-2024-33603

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.
References
Link Resource
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1985 Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:level1:wbr-6012_firmware:r0.40e6:*:*:*:*:*:*:*
cpe:2.3:h:level1:wbr-6012:-:*:*:*:*:*:*:*

History

13 Nov 2024, 18:39

Type Values Removed Values Added
CWE CWE-200 NVD-CWE-noinfo
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1985 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1985 - Exploit, Third Party Advisory
First Time Level1
Level1 wbr-6012
Level1 wbr-6012 Firmware
CPE cpe:2.3:h:level1:wbr-6012:-:*:*:*:*:*:*:*
cpe:2.3:o:level1:wbr-6012_firmware:r0.40e6:*:*:*:*:*:*:*

30 Oct 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-30 14:15

Updated : 2024-11-13 18:39


NVD link : CVE-2024-33603

Mitre link : CVE-2024-33603


JSON object : View

Products Affected

level1

  • wbr-6012_firmware
  • wbr-6012