Unauthenticated Disclosure of Sensitive Information in LevelOne WBR-6012 Router Leaves WiFi Network Vulnerable
CVE-2024-33626
5.3MEDIUM
What is CVE-2024-33626?
The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.
Affected Version(s)
WBR-6012 R0.40e6
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Patrick DeSantis of Cisco Talos.
