ZeroHour

CVE-2024-33610

large

Unauthenticated session-info leak and remote reboot in ELECOM/LOGITEC wireless routers

CVSS 3.1
9.1 critical
EPSS
50%p99
Published
()
Modified
AI analysis

CVE-2024-33610 is a missing-authentication flaw (CWE-288) in the web management interface of affected wireless LAN routers, coordinated by JPCERT/CC. Two admin pages, sessionlist.html and sys_trayentryreboot.html, can be reached over the network without logging in; an unauthenticated HTTP request to each is enough to trigger them. By fetching sessionlist.html an attacker can read logged-in users' session information, including session cookies, which can be replayed to hijack an administrator session (supporting the CVSS 9.1 C:H/I:H impact), and sys_trayentryreboot.html lets the attacker reboot the device remotely. Owners of the affected router models/firmware listed in the vendor advisories are affected; exact model and firmware lists are published by the respective vendors rather than in the CVE record itself. No public proof-of-concept or KEV listing is known, but EPSS gives a 50% probability of exploitation within 30 days (99th percentile), making timely patching a priority.

What to do: Identify your router model and update to the fixed firmware named in the ELECOM/LOGITEC advisory; because leaked session cookies can enable session hijacking, sign out and re-authenticate after patching. Until updated, restrict the admin web UI to the LAN (disable remote/WAN management) and monitor for scanning of these endpoints given the high EPSS probability.

Affected
ELECOM Wireless LAN routers (multiple models; see vendor advisory)
LOGITEC Wireless LAN routers (multiple models; see vendor advisory)
Estimated exposure
largeplausibly on the order of hundreds of thousands of consumer routers (estimate, unverified) — Consumer home-router deployment pattern and the vendors' large retail install base in Japan suggest a six-figure footprint, though the affected-model subset and public scan counts are unknown without the vendor advisories.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

"sessionlist.html" and "sys_trayentryreboot.html" are accessible with no authentication. "sessionlist.html" provides logged-in users' session information including session cookies, and "sys_trayentryreboot.html" allows to reboot the device. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

Weakness
CWE-288
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.