nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-33603 CVE-2024-33603
MEDIUM
Record summary
CVE-2024-33603 has a selected CVSS score of 5.3 (medium).
Description
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 30, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WBR-6012Browse LevelOne / WBR-6012Default status: unknown | CVE List | R0.40e6 | affected |
References
3talosintelligence.com
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1985 talosintelligence.com
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1985