level1 records
33 published records for vendor level1.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-121 Stack-based Buffer Overflow12
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-798 Use of Hard-coded Credentials2
- CWE-259 Use of Hard-coded Password1
The weakness classes this vendor ships most often: where to look.
CWEAll records
33 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-46685No exploit | A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.level1 · wbr-6013 firmware · CWE-259 | Critical9.8 | — | 1.0% | Jul 8, 2024 |
39Monitor | CVE-2024-31151No exploit | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during thelevel1 · wbr-6012 firmware · CWE-798 | Critical9.8 | — | 0.7% | Oct 30, 2024 |
38Monitor | CVE-2024-33699No exploit | The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the adminislevel1 · wbr-6012 firmware · CWE-620 | High8.8 | — | 11.2% | Oct 30, 2024 |
37Monitor | CVE-2024-24777No exploit | A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6.level1 · wbr-6012 firmware · CWE-352 | High8.8 | — | 8.1% | Oct 30, 2024 |
35Monitor | CVE-2024-31152No exploit | The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series level1 · wbr-6012 firmware · CWE-400 | High7.5 | — | 17.8% | Oct 30, 2024 |
35Monitor | CVE-2023-47677No exploit | A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-352 | High8.8 | — | 0.4% | Jul 8, 2024 |
34Monitor | CVE-2024-33623No exploit | A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6.level1 · wbr-6012 firmware · CWE-835 | High7.5 | — | 11.9% | Oct 30, 2024 |
32Monitor | CVE-2024-23309No exploit | The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on clielevel1 · wbr-6012 firmware · CWE-291 | High8.1 | — | 0.9% | Oct 30, 2024 |
32Monitor | CVE-2024-28875No exploit | A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during thelevel1 · wbr-6012 firmware · CWE-798 | High8.1 | — | 0.7% | Oct 30, 2024 |
30Monitor | CVE-2024-33700No exploit | The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attackerlevel1 · wbr-6012 firmware · CWE-20 | High7.5 | — | 0.8% | Oct 30, 2024 |
30Monitor | CVE-2024-28052No exploit | The WBR-6012 is a wireless SOHO router.level1 · wbr-6012 firmware · CWE-131 | High7.5 | — | 0.7% | Oct 30, 2024 |
29Monitor | CVE-2023-50381No exploit | Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-78 | High7.2 | — | 3.2% | Jul 8, 2024 |
29Monitor | CVE-2023-50383No exploit | Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-78 | High7.2 | — | 1.9% | Jul 8, 2024 |
29Monitor | CVE-2023-50382No exploit | Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-78 | High7.2 | — | 1.9% | Jul 8, 2024 |
28Monitor | CVE-2023-50243No exploit | Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.4% | Jul 8, 2024 |
28Monitor | CVE-2023-50239No exploit | Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.4% | Jul 8, 2024 |
28Monitor | CVE-2023-50240No exploit | Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.4% | Jul 8, 2024 |
28Monitor | CVE-2023-47856No exploit | A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.4% | Jul 8, 2024 |
28Monitor | CVE-2023-50244No exploit | Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.4% | Jul 8, 2024 |
28Monitor | CVE-2023-41251No exploit | A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.3% | Jul 8, 2024 |
28Monitor | CVE-2023-45742No exploit | An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-190 | High7.2 | — | 1.2% | Jul 8, 2024 |
28Monitor | CVE-2023-50330No exploit | A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.1% | Jul 8, 2024 |
28Monitor | CVE-2023-49867No exploit | A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.1% | Jul 8, 2024 |
28Monitor | CVE-2023-49593No exploit | Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.level1 · wbr-6013 firmware · CWE-489 | High7.2 | — | 1.1% | Jul 8, 2024 |
28Monitor | CVE-2023-45215No exploit | A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11.realtek · rtl819x jungle software development kit · CWE-121 | High7.2 | — | 1.0% | Jul 8, 2024 |
- CVE-2023-4668539Monitor
A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
CriticalCVSS 9.8No exploitEPSS 1%level1 · wbr-6013 firmwareJul 8, 2024
- CVE-2024-3115139Monitor
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the
CriticalCVSS 9.8No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-3369938Monitor
The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the adminis
HighCVSS 8.8No exploitEPSS 11%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-2477737Monitor
A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6.
HighCVSS 8.8No exploitEPSS 8%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-3115235Monitor
The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series
HighCVSS 7.5No exploitEPSS 18%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2023-4767735Monitor
A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 8.8No exploitEPSS 0%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2024-3362334Monitor
A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6.
HighCVSS 7.5No exploitEPSS 12%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-2330932Monitor
The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on clie
HighCVSS 8.1No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-2887532Monitor
A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the
HighCVSS 8.1No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-3370030Monitor
The LevelOne WBR-6012 router firmware R0.40e6 suffers from an input validation vulnerability within its FTP functionality, enabling attacker
HighCVSS 7.5No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2024-2805230Monitor
The WBR-6012 is a wireless SOHO router.
HighCVSS 7.5No exploitEPSS 1%level1 · wbr-6012 firmwareOct 30, 2024
- CVE-2023-5038129Monitor
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 3%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5038329Monitor
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 2%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5038229Monitor
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 2%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5024328Monitor
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5023928Monitor
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5024028Monitor
Two stack-based buffer overflow vulnerabilities exist in the boa set_RadvdInterfaceParam functionality of Realtek rtl819x Jungle SDK v3.4.11
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-4785628Monitor
A stack-based buffer overflow vulnerability exists in the boa set_RadvdPrefixParam functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5024428Monitor
Two stack-based buffer overflow vulnerabilities exist in the boa formIpQoS functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-4125128Monitor
A stack-based buffer overflow vulnerability exists in the boa formRoute functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-4574228Monitor
An integer overflow vulnerability exists in the boa updateConfigIntoFlash functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-5033028Monitor
A stack-based buffer overflow vulnerability exists in the boa getInfo functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-4986728Monitor
A stack-based buffer overflow vulnerability exists in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024
- CVE-2023-4959328Monitor
Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623.
HighCVSS 7.2No exploitEPSS 1%level1 · wbr-6013 firmwareJul 8, 2024
- CVE-2023-4521528Monitor
A stack-based buffer overflow vulnerability exists in the boa setRepeaterSsid functionality of Realtek rtl819x Jungle SDK v3.4.11.
HighCVSS 7.2No exploitEPSS 1%realtek · rtl819x jungle software development kitJul 8, 2024