CVE-2024-33626: Infoleak
The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33626?
CVE-2024-33626 has been classified as a medium severity vulnerability due to its potential to disclose sensitive information.
How do I fix CVE-2024-33626?
To fix CVE-2024-33626, update the LevelOne WBR-6012 router to the latest firmware version that addresses this vulnerability.
What type of information is disclosed in CVE-2024-33626?
CVE-2024-33626 allows unauthenticated disclosure of sensitive information like the WiFi WPS PIN through a hidden web application page.
Are all versions of LevelOne WBR-6012 affected by CVE-2024-33626?
Only the LevelOne WBR-6012 router firmware version r0.40e6 is affected by CVE-2024-33626.
Who is impacted by CVE-2024-33626?
Users of the LevelOne WBR-6012 router running firmware version r0.40e6 are impacted by CVE-2024-33626.