Level1 develops a focused line of consumer and small-business wireless broadband routers, represented primarily by the WBR-6013 and WBR-6012 product families. Vulnerabilities affecting these devices skew toward a meaningful share of serious outcomes and center on memory-safety and configuration-handling weaknesses including out-of-bounds writes, stack-based buffer overflows, OS command injection, and hard-coded credentials, patterns typical of embedded firmware with long support lifecycles. The device's role as a network gateway and the persistence of older units in service amplify the structural risk: a single vulnerability can affect thousands of deployed endpoints with limited update penetration. Defenders should inventory affected router models, prioritize restricting administrative access, and monitor for signs of exploitation targeting these edge devices. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Level1 over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-46685CRITICAL A hard-coded password vulnerability exists in the telnetd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A set of specially crafted network packets can lead t | Jul 8, 2024 | 9.8 | 31 | NO | NO |
CVE-2024-31151CRITICAL A security flaw involving hard-coded credentials in LevelOne WBR-6012's web services allows attackers to gain unauthorized access during the first 30 seconds post-boot. Other vulne | Oct 30, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-33699HIGH The LevelOne WBR-6012 router's web application has a vulnerability in its firmware version R0.40e6, allowing attackers to change the administrator password and gain higher privileg | Oct 30, 2024 | 8.8 | 29 | NO | NO |
CVE-2024-31152HIGH The LevelOne WBR-6012 router with firmware R0.40e6 is vulnerable to improper resource allocation within its web application, where a series of crafted HTTP requests can cause a reb | Oct 30, 2024 | 7.5 | 28 | NO | NO |
CVE-2024-24777HIGH A cross-site request forgery (CSRF) vulnerability exists in the Web Application functionality of the LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to unautho | Oct 30, 2024 | 8.8 | 28 | NO | NO |
CVE-2024-23309HIGH The LevelOne WBR-6012 router with firmware R0.40e6 has an authentication bypass vulnerability in its web application due to reliance on client IP addresses for authentication. Atta | Oct 30, 2024 | 8.1 | 26 | NO | NO |
CVE-2023-47677HIGH A cross-site request forgery (csrf) vulnerability exists in the boa CSRF protection functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted network request can lea | Jul 8, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-33623HIGH A denial of service vulnerability exists in the Web Application functionality of LevelOne WBR-6012 R0.40e6. A specially crafted HTTP request can lead to a reboot. An attacker can s | Oct 30, 2024 | 7.5 | 23 | NO | NO |
CVE-2023-50381HIGH Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arb | Jul 8, 2024 | 7.2 | 23 | NO | NO |
CVE-2023-49593HIGH Leftover debug code exists in the boa formSysCmd functionality of LevelOne WBR-6013 RER4_A_v3411b_2T2R_LEV_09_170623. A specially crafted network request can lead to arbitrary comm | Jul 8, 2024 | 7.2 | 23 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Level1.
Media articles that mention a CVE ID that affects a product developed by Level1 — matched by CVE ID, not by vendor name.