First published: Wed Oct 30 2024(Updated: )
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.
Credit: talos-cna@cisco.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Level1 Wbr-6012 Firmware | =r0.40e6 | |
Level1 Wbr-6012 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-33603 has been assigned a medium severity level due to the potential for information disclosure.
To mitigate CVE-2024-33603, ensure that your LevelOne WBR-6012 router's firmware is updated to the latest version available.
CVE-2024-33603 allows unauthorized access to sensitive data, including memory addresses and IP addresses from system log files.
Users of the LevelOne WBR-6012 router running firmware version r0.40e6 are specifically affected by CVE-2024-33603.
Yes, CVE-2024-33603 could potentially facilitate session hijacking and other related attacks due to compromised sensitive information.