Hard-coded credentials vulnerability in LevelOne WBR-6012 web services
CVE-2024-28875

8.1HIGH

Key Information:

Vendor

Levelone

Status
Vendor
CVE Published:
30 October 2024

What is CVE-2024-28875?

A security vulnerability in the LevelOne WBR-6012 arises from the presence of hard-coded credentials within its web services. This flaw allows attackers to gain unauthorized administrative access to the device within the first 30 seconds after booting. The security risk further expands as other vulnerabilities may trigger an unintended reboot, effectively bypassing the initial time window for exploitation. The hard-coded backdoor string, located at a specific memory address, can be exploited by comparing input against the string '@m!t2K1', enabling malicious actors to reach administrative access levels. Proper measures are essential to mitigate this risk.

Affected Version(s)

WBR-6012 R0.40e6

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Discovered by Francesco Benvenuto and Patrick DeSantis of Cisco Talos.
.