CVE-2024-33603: Infoleak
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33603?
CVE-2024-33603 has been assigned a medium severity level due to the potential for information disclosure.
How do I fix CVE-2024-33603?
To mitigate CVE-2024-33603, ensure that your LevelOne WBR-6012 router's firmware is updated to the latest version available.
What data can be exposed due to CVE-2024-33603?
CVE-2024-33603 allows unauthorized access to sensitive data, including memory addresses and IP addresses from system log files.
Who is affected by CVE-2024-33603?
Users of the LevelOne WBR-6012 router running firmware version r0.40e6 are specifically affected by CVE-2024-33603.
Can CVE-2024-33603 lead to other attacks?
Yes, CVE-2024-33603 could potentially facilitate session hijacking and other related attacks due to compromised sensitive information.