Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
References
| Link | Resource |
|---|---|
| https://news.ycombinator.com/item?id=40917312 | Issue Tracking |
| https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ | Press/Media Coverage |
| https://news.ycombinator.com/item?id=40917312 | Issue Tracking |
| https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ | Press/Media Coverage |
Configurations
History
No history.
Information
Published : 2024-07-09 20:15
Updated : 2025-06-30 15:15
NVD link : CVE-2024-40750
Mitre link : CVE-2024-40750
CVE.ORG link : CVE-2024-40750
JSON object : View
Products Affected
linksys
- mx6200_firmware
- mbe7000
- mx6200
- mbe7000_firmware
CWE
CWE-312
Cleartext Storage of Sensitive Information
