CVE-2024-33610
largeUnauthenticated session-info leak and remote reboot in ELECOM/LOGITEC wireless routers
CVE-2024-33610 is a missing-authentication flaw (CWE-288) in the web management interface of affected wireless LAN routers, coordinated by JPCERT/CC. Two admin pages, sessionlist.html and sys_trayentryreboot.html, can be reached over the network without logging in; an unauthenticated HTTP request to each is enough to trigger them. By fetching sessionlist.html an attacker can read logged-in users' session information, including session cookies, which can be replayed to hijack an administrator session (supporting the CVSS 9.1 C:H/I:H impact), and sys_trayentryreboot.html lets the attacker reboot the device remotely. Owners of the affected router models/firmware listed in the vendor advisories are affected; exact model and firmware lists are published by the respective vendors rather than in the CVE record itself. No public proof-of-concept or KEV listing is known, but EPSS gives a 50% probability of exploitation within 30 days (99th percentile), making timely patching a priority.
What to do: Identify your router model and update to the fixed firmware named in the ELECOM/LOGITEC advisory; because leaked session cookies can enable session hijacking, sign out and re-authenticate after patching. Until updated, restrict the admin web UI to the LAN (disable remote/WAN management) and monitor for scanning of these endpoints given the high EPSS probability.
| ELECOM Wireless LAN routers (multiple models; see vendor advisory) | — |
| LOGITEC Wireless LAN routers (multiple models; see vendor advisory) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].
- Weakness
- CWE-288
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.