First published: Sat Nov 21 2015(Updated: )
Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password of the day" issue.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Arris Na Model 862 Gw Mono Firmware | =ts070593c_073013 | |
Arris Na Model 862 Gw Mono Firmware | =ts0703128_100611 | |
Arris Na Model 862 Gw Mono Firmware | =ts0703135_112211 | |
Arris Na Model 862 Gw Mono Firmware | =ts0705125_062314 | |
Arris Na Model 862 Gw Mono Firmware | =ts0705125d_031115 | |
Arris DG860A | ||
Arris Tg862a | ||
Arris Tg862g |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-5149 has a medium severity rating due to the risk of unauthorized access to the affected devices.
To fix CVE-2009-5149, upgrade the firmware of Arris DG860A, TG862A, and TG862G devices to the latest version that addresses the predictable technician passwords issue.
CVE-2009-5149 affects Arris DG860A, TG862A, and TG862G devices running specific firmware versions from TS0703128_100611 to TS0705125D_031115.
The main issue with CVE-2009-5149 is the predictable technician passwords that can be exploited, allowing attackers to gain remote access via the web management interface.
No, only specific firmware versions in the TS0703128 through TS0705125D range are vulnerable to CVE-2009-5149.