Unauthenticated Disclosure of Sensitive Information in LevelOne WBR-6012 Router Leaves WiFi Network Vulnerable
CVE-2024-33626

5.3MEDIUM

Key Information:

Vendor

Levelone

Status
Vendor
CVE Published:
30 October 2024

What is CVE-2024-33626?

The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.

Affected Version(s)

WBR-6012 R0.40e6

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Patrick DeSantis of Cisco Talos.
.