Levelone Wbr-6012 vulnerabilities
12 known vulnerabilities affecting levelone/wbr-6012.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH8MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-33699P2HIGHCVSS 8.8vR0.40e62024-10-30
CVE-2024-33699 [HIGH] CWE-620 CVE-2024-33699: The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6,
The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.
nvd
CVE-2024-31151P2CRITICALCVSS 9.8vR0.40e62024-10-30
CVE-2024-31151 [CRITICAL] CWE-798 CVE-2024-31151: A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attacker
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The password string can be found at addresses 0x 803cdd0f and 0x803da3e6:
803
nvd
CVE-2024-31152P3HIGHCVSS 7.5vR0.40e62024-10-30
CVE-2024-31152 [HIGH] CWE-400 CVE-2024-31152: The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation wit
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reboot. This could lead to network service interruptions.
nvd
CVE-2024-24777P3HIGHCVSS 8.8vR0.40e62024-10-30
CVE-2024-24777 [HIGH] CWE-352 CVE-2024-24777: A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious web page to trigger this vulnerability.
nvd
CVE-2024-23309P3HIGHCVSS 8.1vR0.40e62024-10-30
CVE-2024-23309 [HIGH] CWE-291 CVE-2024-23309: The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its
The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Attackers could spoof an IP address to gain unauthorized access without needing a session token.
nvd
CVE-2024-28875P3HIGHCVSS 8.1vR0.40e62024-10-30
CVE-2024-28875 [HIGH] CWE-798 CVE-2024-28875: A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attacker
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be found at address 0x80100910
80100910 40 6d 21 74 ds "@
nvd
CVE-2024-33623P3HIGHCVSS 7.5vR0.40e62024-10-30
CVE-2024-33623 [HIGH] CWE-835 CVE-2024-33623: A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2024-28052P3HIGHCVSS 7.5vR0.40e62024-10-30
CVE-2024-28052 [HIGH] CWE-131 CVE-2024-28052: The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gatew
The WBR-6012 is a wireless SOHO router. It is a low-cost device which functions as an internet gateway for homes and small offices while aiming to be easy to configure and operate. In addition to providing a WiFi access point, the device serves as a 4-port wired router and implements a variety of common SOHO router capabilities such as port forwarding
nvd
CVE-2024-33700P3HIGHCVSS 7.5vR0.40e62024-10-30
CVE-2024-33700 [HIGH] CWE-20 CVE-2024-33700: The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within
The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackers to cause a denial of service through a series of malformed FTP commands. This can lead to device reboots and service disruption.
nvd
CVE-2024-33603P3MEDIUMCVSS 5.3vR0.40e62024-10-30
CVE-2024-33603 [MEDIUM] CWE-200 CVE-2024-33603: The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, whi
The LevelOne WBR-6012 router has an information disclosure vulnerability in its web application, which allows unauthenticated users to access a verbose system log page and obtain sensitive data, such as memory addresses and IP addresses for login attempts. This flaw could lead to session hijacking due to the device's reliance on IP address for authe
nvd
CVE-2024-32946P4MEDIUMCVSS 5.9vR0.40e62024-10-30
CVE-2024-32946 [MEDIUM] CWE-319 CVE-2024-32946: A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive informat
A vulnerability in the LevelOne WBR-6012 router's firmware version R0.40e6 allows sensitive information to be transmitted in cleartext via Web and FTP services, exposing it to network sniffing attacks.
nvd
CVE-2024-33626P4MEDIUMCVSS 5.3vR0.40e62024-10-30
CVE-2024-33626 [MEDIUM] CWE-200 CVE-2024-33626: The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthe
The LevelOne WBR-6012 router contains a vulnerability within its web application that allows unauthenticated disclosure of sensitive information, such as the WiFi WPS PIN, through a hidden page accessible by an HTTP request. Disclosure of this information could enable attackers to connect to the device's WiFi network.
nvd