Description

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be found at address 0x80100910 80100910 40 6d 21 74 ds "@m!t2K1" 32 4b 31 00 It is referenced by the function located at 0x800b78b0 and is used as shown in the pseudocode below: if ((SECOND_FROM_BOOT_TIME < 300) && (is_equal = strcmp(password,"@m!t2K1")) { return 1;} Where 1 is the return value to admin-level access (0 being fail and 3 being user).

INFO

Published Date :

2024-10-30T13:35:19.982Z

Last Modified :

2025-11-03T21:54:34.037Z

Source :

talos
AFFECTED PRODUCTS

The following products are affected by CVE-2024-28875 vulnerability.

Vendors Products
Level1
  • Wbr-6012
  • Wbr-6012 Firmware
Levelone
  • Wbr-6012
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-28875.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact