First published: Wed Oct 30 2024(Updated: )
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Level1 WBR-6012 Firmware | =r0.40e6 | |
Level1 WBR-6012 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-24777 is classified as medium due to potential unauthorized access via CSRF attacks.
To fix CVE-2024-24777, update the firmware of the LevelOne WBR-6012 to the latest version that addresses the CSRF vulnerability.
CVE-2024-24777 is a cross-site request forgery (CSRF) vulnerability.
Users of the LevelOne WBR-6012 firmware version r0.40e6 are affected by CVE-2024-24777.
An attacker can exploit CVE-2024-24777 to gain unauthorized access by triggering a specially crafted HTTP request.