CVE-2024-31151: Critical severity Level1 Wbr-6012 Firmware vulnerability

Published Oct 30, 2024
·
Updated

A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be found at addresses 0x 803cdd0f and 0x803da3e6: 803cdd0f 41 72 69 65 ds "AriesSerenaCairryNativitaMegan" 73 53 65 72 65 6e 61 43 ... It is referenced by the function at 0x800b78b0 and simplified in the pseudocode below: if (isequal = strcmp(password,"AriesSerenaCairryNativitaMegan"){ ret = 3;} Where 3 is the return value to user-level access (0 being fail and 1 being admin/backdoor). While there's no legitimate functionality to change this password, once authenticated it is possible manually make a change by taking advantage of TALOS-2024-XXXXX using HTTP POST paramater "Pu" (new user password) in place of "Pa" (new admin password).

Affected Software

2 affected components
All of the following
Level1 Wbr-6012 Firmware=r0.40e6
Level1 Wbr-6012

Event History

Oct 30, 2024
CVE Published
via MITRE·01:35 PM
Data Sourced
via MITRE·01:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-31151?

CVE-2024-31151 is classified as a high-severity vulnerability due to the potential for unauthorized access.

2

How do I fix CVE-2024-31151?

To mitigate CVE-2024-31151, it is recommended to disable unnecessary web services and change default credentials after boot.

3

What systems are affected by CVE-2024-31151?

CVE-2024-31151 specifically affects the LevelOne WBR-6012 with firmware version r0.40e6.

4

What is the nature of the vulnerability CVE-2024-31151?

CVE-2024-31151 is caused by hard-coded credentials in the web services of the LevelOne WBR-6012.

5

Can CVE-2024-31151 be exploited remotely?

Yes, CVE-2024-31151 can be exploited remotely within the first 30 seconds post-boot or during forced reboots.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203