Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://www.verizon.com/ | vendor advisory |
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5701.php | third party advisory exploit |