Hard-coded credentials vulnerability in LevelOne WBR-6012 web services
CVE-2024-28875
8.1HIGH
What is CVE-2024-28875?
A security vulnerability in the LevelOne WBR-6012 arises from the presence of hard-coded credentials within its web services. This flaw allows attackers to gain unauthorized administrative access to the device within the first 30 seconds after booting. The security risk further expands as other vulnerabilities may trigger an unintended reboot, effectively bypassing the initial time window for exploitation. The hard-coded backdoor string, located at a specific memory address, can be exploited by comparing input against the string '@m!t2K1', enabling malicious actors to reach administrative access levels. Proper measures are essential to mitigate this risk.
Affected Version(s)
WBR-6012 R0.40e6
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Francesco Benvenuto and Patrick DeSantis of Cisco Talos.