CVE Vulnerabilities

CVE-2024-32946

Cleartext Transmission of Sensitive Information

Published: Oct 30, 2024 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the LevelOne WBR-6012 routers firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.

Weakness

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Affected Software

Name Vendor Start Version End Version
Wbr-6012_firmware Level1 r0.40e6 (including) r0.40e6 (including)

Potential Mitigations

References