The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Link | Tags |
---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2024-1984 | third party advisory exploit |
https://www.talosintelligence.com/vulnerability_reports/TALOS-2024-1984 |