← back
CVE-2024-12011

CVE-2024-12011

CVSS 7.6 HIGHEPSS 0.4%CWE-126
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.6EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
13 Feb 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A CWE-126 “Buffer Over-read” was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid authentication tokens from the process memory associated to users currently logged to the system and bypass the authentication mechanism.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
Affected products
Zettler · 130.8005

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →