CVE-2024-51431: Critical severity lb-link bl-wr1300h firmware vulnerability
Published Nov 1, 2024
·Updated
LB-LINK BL-WR 1300H v.1.0.4 contains hardcoded credentials stored in /etc/shadow which are easily guessable.
Affected Software
2 affected components
All of the following
LB-LINK Bl-wr1300h Firmware=1.0.4
LB-LINK Bl-wr1300h
Event History
Nov 1, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-51431?
CVE-2024-51431 is considered a high severity vulnerability due to the presence of hardcoded credentials.
2
How do I fix CVE-2024-51431?
To fix CVE-2024-51431, update the firmware to a version that does not store hardcoded credentials.
3
What devices are affected by CVE-2024-51431?
CVE-2024-51431 specifically affects the LB-LINK BL-WR 1300H with firmware version 1.0.4.
4
What risks are associated with CVE-2024-51431?
The risks associated with CVE-2024-51431 include unauthorized access to the device and its network.
5
Is there a patch available for CVE-2024-51431?
Yes, a patch is available through firmware updates that address the hardcoded credential issue in CVE-2024-51431.