First published: Thu Aug 29 2019(Updated: )
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/basic_sett.html. Any user connected to the Wi-Fi can exploit this.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Commscope Tr4400 Firmware | <=a1.00.004-180301 | |
Commscope Tr4400 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-15806 is critical with a score of 9.8.
CVE-2019-15806 is an authentication bypass vulnerability.
CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are affected by CVE-2019-15806.
CVE-2019-15806 allows any user connected to the Wi-Fi to bypass authentication and gain access to the administrative interface.
To fix CVE-2019-15806, upgrade the firmware of CommScope ARRIS TR4400 devices to a version higher than A1.00.004-180301.