← Vulnerability feed

Vulnerability record · CVE-2024-33603 · published 30 October 2024

CVE-2024-33603: Level1 wbr-6012 firmware information exposure vulnerability

Level1 · Wbr 6012 Firmware

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.

5.3 CVSS 3.1 Medium EPSS 8.6% · top 5.1% CWE-200 · Information exposure
5.3CVSS 3.1 base score
8.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-33603 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-31151Level1 wbr-6012 firmware hard-coded credentials vulnerabilityA security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30…EPSS 0.71%8.8CVE-2024-33699Level1 wbr-6012 firmware vulnerabilityThe LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator pa…EPSS 11%8.8CVE-2024-24777Level1 wbr-6012 firmware cross-site request forgery vulnerabilityA cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted H…EPSS 8.1%8.1CVE-2024-23309Level1 wbr-6012 firmware vulnerabilityThe LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP add…EPSS 0.92%8.1CVE-2024-28875Level1 wbr-6012 firmware hard-coded credentials vulnerabilityA security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30…EPSS 0.69%7.5CVE-2024-33700Level1 wbr-6012 firmware improper input validation vulnerabilityThe LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to caus…EPSS 0.82%7.5CVE-2024-33623Level1 wbr-6012 firmware vulnerabilityA denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead…EPSS 12%7.5CVE-2024-31152Level1 wbr-6012 firmware uncontrolled resource consumption vulnerabilityThe LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafte…EPSS 18%

Source: NIST National Vulnerability Database (record CVE-2024-33603), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.