CVE-2024-28875: High severity Level1 Wbr-6012 Firmware vulnerability

Published Oct 30, 2024
·
Updated

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be found at address 0x80100910 80100910 40 6d 21 74 ds "@m!t2K1" 32 4b 31 00 It is referenced by the function located at 0x800b78b0 and is used as shown in the pseudocode below: if ((SECONDFROMBOOTTIME < 300) && (isequal = strcmp(password,"@m!t2K1")) { return 1;} Where 1 is the return value to admin-level access (0 being fail and 3 being user).

Affected Software

2 affected components
All of the following
Level1 Wbr-6012 Firmware=r0.40e6
Level1 Wbr-6012

Event History

Oct 30, 2024
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-28875?

CVE-2024-28875 is considered a high-severity vulnerability due to the potential for unauthorized access via hard-coded credentials.

2

How do I fix CVE-2024-28875?

Fixing CVE-2024-28875 involves updating the LevelOne WBR-6012 firmware to the latest version provided by the manufacturer.

3

What impact does CVE-2024-28875 have on LevelOne WBR-6012 security?

CVE-2024-28875 allows attackers to gain unauthorized access during the vulnerable period post-boot, posing serious security risks.

4

Can CVE-2024-28875 be exploited remotely?

Yes, CVE-2024-28875 can be exploited remotely if an attacker is aware of the hard-coded credentials.

5

What devices are affected by CVE-2024-28875?

The affected device for CVE-2024-28875 is the LevelOne WBR-6012 with firmware version r0.40e6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203