CVE-2019-15806: Weak Encryption
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basicsett.html. Any user connected to the Wi-Fi can exploit this.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-15806?
The severity of CVE-2019-15806 is critical with a score of 9.8.
What is the vulnerability of CVE-2019-15806?
CVE-2019-15806 is an authentication bypass vulnerability.
Which devices are affected by CVE-2019-15806?
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are affected by CVE-2019-15806.
How does CVE-2019-15806 work?
CVE-2019-15806 allows any user connected to the Wi-Fi to bypass authentication and gain access to the administrative interface.
How can I fix CVE-2019-15806?
To fix CVE-2019-15806, upgrade the firmware of CommScope ARRIS TR4400 devices to a version higher than A1.00.004-180301.