The LevelOne WBR-6012 routers web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileges without the current password.
When setting a new password for a user, the product does not require knowledge of the original password, or using another form of authentication.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wbr-6012_firmware | Level1 | r0.40e6 (including) | r0.40e6 (including) |