CVE-2024-31151: Critical severity Level1 Wbr-6012 Firmware vulnerability
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be found at addresses 0x 803cdd0f and 0x803da3e6: 803cdd0f 41 72 69 65 ds "AriesSerenaCairryNativitaMegan" 73 53 65 72 65 6e 61 43 ... It is referenced by the function at 0x800b78b0 and simplified in the pseudocode below: if (isequal = strcmp(password,"AriesSerenaCairryNativitaMegan"){ ret = 3;} Where 3 is the return value to user-level access (0 being fail and 1 being admin/backdoor). While there's no legitimate functionality to change this password, once authenticated it is possible manually make a change by taking advantage of TALOS-2024-XXXXX using HTTP POST paramater "Pu" (new user password) in place of "Pa" (new admin password).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-31151?
CVE-2024-31151 is classified as a high-severity vulnerability due to the potential for unauthorized access.
How do I fix CVE-2024-31151?
To mitigate CVE-2024-31151, it is recommended to disable unnecessary web services and change default credentials after boot.
What systems are affected by CVE-2024-31151?
CVE-2024-31151 specifically affects the LevelOne WBR-6012 with firmware version r0.40e6.
What is the nature of the vulnerability CVE-2024-31151?
CVE-2024-31151 is caused by hard-coded credentials in the web services of the LevelOne WBR-6012.
Can CVE-2024-31151 be exploited remotely?
Yes, CVE-2024-31151 can be exploited remotely within the first 30 seconds post-boot or during forced reboots.