CVE-2023-40038
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
27/12/2023
Last modified:
04/01/2024
Description
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:arris:dg860a_firmware:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:arris:dg860a:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:arris:dg1670a_firmware:ts0901203b6_020420_16xx.gw_pc20_tw:*:*:*:*:*:*:* | ||
cpe:2.3:h:arris:dg1670a:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page