CVE-2024-40112 is a Local File Inclusion (LFI) vulnerability affecting Sitecom WLX-2006 Wall Mount Range Extender N300 v1.5 and earlier, allowing attackers to read arbitrary files by manipulating the "language" cookie. This vulnerability has a CVSS score of 5.9 (Medium), indicating a low attack complexity and local attack vector, with potential for low impact on confidentiality, integrity, and availability. While the vulnerability could lead to sensitive information disclosure, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.5CPE matchmatch criteria | cpe:2.3:o:sitecom:wlx-2006_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.