CVE-2024-33373

MEDIUM

Lb-link Bl-w1210m Firmware - IDOR

Title source: rule
STIX 2.1

Description

An issue in the LB-LINK BL-W1210M v2.0 router allows attackers to bypass password complexity requirements and set single digit passwords for authentication. This vulnerability can allow attackers to access the router via a brute-force attack.

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 13.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
lb-link/bl-w1210m_firmware
Published Jun 14, 2024
Tracked Since Feb 18, 2026