Linksys Velop Pro 6E 1.0.8 MX6200_1.0.8.215731 and 7 1.0.10.215314 devices send cleartext Wi-Fi passwords over the public Internet during app-based installation.
References
Link | Resource |
---|---|
https://news.ycombinator.com/item?id=40917312 | Issue Tracking |
https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ | Press/Media Coverage |
https://news.ycombinator.com/item?id=40917312 | Issue Tracking |
https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ | Press/Media Coverage |
Configurations
History
30 Jun 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Linksys mbe7000 Firmware
Linksys Linksys mx6200 Linksys mx6200 Firmware Linksys mbe7000 |
|
CPE | cpe:2.3:h:linksys:mx6200:-:*:*:*:*:*:*:* cpe:2.3:h:linksys:mbe7000:-:*:*:*:*:*:*:* cpe:2.3:o:linksys:mx6200_firmware:1.0.8.215731:*:*:*:*:*:*:* cpe:2.3:o:linksys:mbe7000_firmware:1.0.10.215314:*:*:*:*:*:*:* |
|
References | () https://news.ycombinator.com/item?id=40917312 - Issue Tracking | |
References | () https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ - Press/Media Coverage |
Information
Published : 2024-07-09 20:15
Updated : 2025-06-30 15:15
NVD link : CVE-2024-40750
Mitre link : CVE-2024-40750
CVE.ORG link : CVE-2024-40750
JSON object : View
Products Affected
linksys
- mx6200_firmware
- mx6200
- mbe7000
- mbe7000_firmware
CWE
CWE-312
Cleartext Storage of Sensitive Information