CVE-2019-15805: Weak Encryption
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can exploit this.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-15805.
What is the severity of CVE-2019-15805?
The severity of CVE-2019-15805 is critical, with a severity value of 9.8.
What is the affected software?
The affected software is CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301.
How does the vulnerability CVE-2019-15805 allow an authentication bypass?
The vulnerability CVE-2019-15805 allows an authentication bypass by including the current base64 encoded password within the login page of the administrative interface.
Who can exploit the vulnerability CVE-2019-15805?
Any user connected to the Wi-Fi can exploit the vulnerability CVE-2019-15805.