CVE-2024-23309
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD
Description
The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.
Affected (1)
Products: Level1: Wbr 6012 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version r0.40e6 |
| Running on/with | Platform Versions |
|---|---|
Level1 Wbr 6012 | All versions |
Related CWEs
References (2)
Source: talos-cna@cisco.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.