CVE-2024-23309
The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.92%
- CWE
- CWE-291
- Published
- 2024-10-30
- Last modified
- 2026-03-13
Affected products
- LevelOne WBR-6012
Weakness type
Related vulnerabilities
- CVE-2026-86485 — In JetBrains YouTrack before 2026.2.18634 iP spoofing via HTTP headers allowed forged Bitbucket...
- CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability
- CVE-2026-4252 — Tenda AC8 IPv6 check_is_ipv6 ip address for authentication
- CVE-2025-66602 — A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation....
- CVE-2025-59101 — Insufficient Session Management in dormakaba access manager
- CVE-2025-34202 — Vasion Print (formerly PrinterLogic) Insecure Access to Docker Instances WAN
- CVE-2024-32765 — QTS, QuTS hero
- CVE-2023-7211 — Uniway Router Administrative Web Interface reliance on ip address for authentication