Vulnerability Description
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Verizon | 4G Lte Network Extender Firmware | 0.4.038.2131 |
| Verizon | 4G Lte Network Extender | - |
Related Weaknesses (CWE)
References
- https://www.verizon.com/Vendor Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5701.phpExploitThird Party Advisory
- https://www.verizon.com/Vendor Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5701.phpExploitThird Party Advisory
FAQ
What is CVE-2022-29729?
CVE-2022-29729 is a vulnerability with a CVSS score of 7.5 (HIGH). Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the we...
How severe is CVE-2022-29729?
CVE-2022-29729 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-29729?
Check the references section above for vendor advisories and patch information. Affected products include: Verizon 4G Lte Network Extender Firmware, Verizon 4G Lte Network Extender.