CSRF Vulnerability in LevelOne WBR-6012 R0.40e6 Leads to Unauthorized Access
CVE-2024-24777

8.8HIGH

Key Information:

Vendor

Levelone

Status
Vendor
CVE Published:
30 October 2024

What is CVE-2024-24777?

A vulnerability in the web application functionality of the LevelOne WBR-6012 router exposes it to cross-site request forgery (CSRF) attacks. This vulnerability allows an unauthorized user to send specially crafted HTTP requests, which can lead to unauthorized actions being carried out on behalf of the legitimate user. By staging a malicious web page, an attacker can exploit this weakness to gain unauthorized access to user accounts or perform actions that compromise user integrity and security. Protecting against this vulnerability requires proactive measures to ensure web requests are verified and origins validated.

Affected Version(s)

WBR-6012 R0.40e6

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Patrick DeSantis of Cisco Talos.
.