Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary command execution.
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wbr-6013_firmware | Level1 | rer4_a_v3411b_2t2r_lev_09_170623 (including) | rer4_a_v3411b_2t2r_lev_09_170623 (including) |