Hard-coded credentials vulnerability in LevelOne WBR-6012 web services
CVE-2024-28875
What is CVE-2024-28875?
A security vulnerability in the LevelOne WBR-6012 arises from the presence of hard-coded credentials within its web services. This flaw allows attackers to gain unauthorized administrative access to the device within the first 30 seconds after booting. The security risk further expands as other vulnerabilities may trigger an unintended reboot, effectively bypassing the initial time window for exploitation. The hard-coded backdoor string, located at a specific memory address, can be exploited by comparing input against the string '@m!t2K1', enabling malicious actors to reach administrative access levels. Proper measures are essential to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
WBR-6012 R0.40e6
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
