CVE-2019-9555
Severity CVSS v4.0:
Pending analysis
Type:
CWE-331
Insufficient Entropy
Publication date:
05/03/2019
Last modified:
24/08/2020
Description
Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:sagemcom:f\@st_5260_firmware:0.4.39:*:*:*:*:*:*:* | ||
| cpe:2.3:h:sagemcom:f\@st_5260:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



