Vulnerability Description
Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linksys | Mx6200 Firmware | 1.0.8.215731 |
| Linksys | Mx6200 | - |
| Linksys | Mbe7000 Firmware | 1.0.10.215314 |
| Linksys | Mbe7000 | - |
Related Weaknesses (CWE)
References
- https://news.ycombinator.com/item?id=40917312Issue Tracking
- https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-tPress/Media Coverage
- https://news.ycombinator.com/item?id=40917312Issue Tracking
- https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-tPress/Media Coverage
FAQ
What is CVE-2024-40750?
CVE-2024-40750 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
How severe is CVE-2024-40750?
CVE-2024-40750 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-40750?
Check the references section above for vendor advisories and patch information. Affected products include: Linksys Mx6200 Firmware, Linksys Mx6200, Linksys Mbe7000 Firmware, Linksys Mbe7000.