CVE-2024-23309 - CVE House
Back to Database
Status published Critical CVE-2024-23309

The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication...

Vulnerability Description

The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-23309

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Discovered by Patrick DeSantis of Cisco Talos.

Affected Vendor

Affected Software

WBR-6012
Vulnerable Versions:
R0.40e6

Timeline

Official Publish: October 30th, 2024
Last Modified: October 30th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.