CVE-2024-40112
Last modified
CVE-2024-40112 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
A Local File Inclusion (LFI) vulnerability exists in Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and before, which allows an attacker to manipulate the "language" cookie to include arbitrary files from the server. This vulnerability can be exploited to disclose sensitive information.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sitecom | Wlx-2006 Firmware | <= 1.5 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-40112?
How severe is CVE-2024-40112?
How do I fix CVE-2024-40112?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-40096The com.cascadialabs.who (aka Who - Caller ID, Spam Block) a…3.3
- CVE-2024-4010The Email Subscribers by Icegram Express plugin for WordPres…8.8
- CVE-2024-40101A Reflected Cross-site scripting (XSS) vulnerability exists …6.1
- CVE-2024-4011An issue was discovered in GitLab CE/EE affecting all versio…4.3
- CVE-2024-40110Sourcecodester Poultry Farm Management System v1.0 contains …9.8
- CVE-2024-40111A persistent (stored) cross-site scripting (XSS) vulnerabili…4.8
- CVE-2024-40113Sitecom WLX-2006 Wall Mount Range Extender N300 v.1.5 and be…6.5
- CVE-2024-40114A Cross Site Scripting (XSS) vulnerability in Sitecom WLX-20…6.1
- CVE-2024-40116An issue in Solar-Log 1000 before v2.8.2 and build 52-23.04.…8.1
- CVE-2024-40117Incorrect access control in Solar-Log 1000 before v2.8.2 and…9.8
- CVE-2024-40119Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v…8.8
- CVE-2024-4012Rejected reason: This CVE ID has been rejected or withdrawn …
Are you affected by CVE-2024-40112?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
