# CVE-2024-42001

## Summary

- **CVE ID:** CVE-2024-42001
- **Severity:** MEDIUM
- **CVSS Score:** 8.6 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-425
- **Published:** Aug 8, 2024
- **Last Modified:** Mar 13, 2026

## Description

An improper authentication vulnerability affecting Vonets





 

 industrial wifi bridge relays and wifi bridge repeaters, software versions 
3.3.23.6.9 and prior enables an unauthenticated remote attacker to 
bypass authentication via a specially crafted direct request when 
another user has an active session.

## Affected Products

- Vonets — VAR1200-H (0)
- Vonets — VAR1200-L (0)
- Vonets — VAR600-H (0)
- Vonets — VAP11AC (0)
- Vonets — VAP11G-500S (0)
- Vonets — VBG1200 (0)
- Vonets — VAP11S-5G (0)
- Vonets — VAP11S (0)
- Vonets — VAR11N-300 (0)
- Vonets — VAP11G-300 (0)
- Vonets — VAP11N-300 (0)
- Vonets — VAP11G (0)
- Vonets — VAP11G-500 (0)
- Vonets — VGA-1000 (0)

## References

- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-08)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.68%
- **EPSS Percentile:** 50.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._