CVE-2024-40112
5.9
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Exploitability: 2.5 / Impact: 3.4
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.
Affected (1)
Products: Sitecom: Wlx 2006 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.5 |
| Running on/with | Platform Versions |
|---|---|
Sitecom Wlx 2006 | All versions |
References (2)
Source: cve@mitre.org
Broken Link
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.