Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://i.ebayimg.com/images/g/ByAAAOSwQCFi2b50/s-l1600.jpg | product |
https://github.com/actuator/cve/blob/main/Arris/CVE-2023-40038 | third party advisory |