CRITICAL🇵🇱 Wersja polska

CVE-2024-23309

CVSS 9.0v3.1pub. 2024-10-30upd. 2024-11-21

The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.

🤖 AI Analysis
How it works

The router's web application bases its authentication mechanism on the client's IP address instead of a secure session token (CWE-291 — reliance on IP address for authentication). An attacker can perform an IP spoofing attack by impersonating a trusted address that the application will recognize as authenticated. Since identity verification does not require possession of a valid session token, a forged IP address is sufficient to gain full access to the management interface.

Impact

An attacker can gain unauthorized access to the router's management interface, which may lead to complete device takeover, modification of its configuration, interception of network traffic, and violation of confidentiality, integrity, and availability of data on the network.

Mitigation & patch

Patches available from the manufacturer should be applied in accordance with the references. As a temporary measure, it is recommended to restrict access to the router's web interface only to trusted hosts and to segment the management network.

Who is affected

LevelOne WBR-6012 with firmware R0.40e6

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Level1 Wbr 6012

    HW
    Level1
    all versions
  • Level1 Wbr 6012 Firmware

    OS
    Level1
    r0.40e6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-33699CRITICAL9.9PL ✓same product

LevelOne WBR-6012: zmiana hasła admina bez uwierzytelnienia

CVE-2024-28875HIGH8.1same product

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain ...

CVE-2024-31151HIGH8.1same product

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain ...

CVE-2024-24777HIGH8.8same product

A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne ...

CVE-2024-33700HIGH7.5same product

The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP fu...