Vulnerability Description
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Arris | Dg860A Firmware | - |
| Arris | Dg860A | - |
| Arris | Dg1670A Firmware | ts0901203b6_020420_16xx.gw_pc20_tw |
| Arris | Dg1670A | - |
Related Weaknesses (CWE)
References
- https://github.com/actuator/cve/blob/main/Arris/CVE-2023-40038Third Party Advisory
- https://i.ebayimg.com/images/g/ByAAAOSwQCFi2b50/s-l1600.jpgProduct
- https://github.com/actuator/cve/blob/main/Arris/CVE-2023-40038Third Party Advisory
- https://i.ebayimg.com/images/g/ByAAAOSwQCFi2b50/s-l1600.jpgProduct
FAQ
What is CVE-2023-40038?
CVE-2023-40038 is a vulnerability with a CVSS score of 8.8 (HIGH). Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, ...
How severe is CVE-2023-40038?
CVE-2023-40038 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-40038?
Check the references section above for vendor advisories and patch information. Affected products include: Arris Dg860A Firmware, Arris Dg860A, Arris Dg1670A Firmware, Arris Dg1670A.