CVE-2019-9555

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
05/03/2019
Last modified:
24/08/2020

Description

Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:sagemcom:f\@st_5260_firmware:0.4.39:*:*:*:*:*:*:*
cpe:2.3:h:sagemcom:f\@st_5260:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools