A security flaw involving hard-coded credentials in...
High severity
Unreviewed
Published
Oct 30, 2024
to the GitHub Advisory Database
•
Updated Oct 30, 2024
Description
Published by the National Vulnerability Database
Oct 30, 2024
Published to the GitHub Advisory Database
Oct 30, 2024
Last updated
Oct 30, 2024
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulnerabilities can force a reboot, circumventing the initial time restriction for exploitation.The backdoor string can be found at address 0x80100910
It is referenced by the function located at 0x800b78b0 and is used as shown in the pseudocode below:
Where 1 is the return value to admin-level access (0 being fail and 3 being user).
References