CVE-2022-29729: High severity verizon 4g lte network extender firmware vulnerability
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-29729?
CVE-2022-29729 is classified as a high severity vulnerability due to the use of weak default admin passwords that can be easily exploited.
How do I fix CVE-2022-29729?
To mitigate CVE-2022-29729, users should change the default admin password to a strong, unique password immediately after setup.
What systems are affected by CVE-2022-29729?
CVE-2022-29729 affects the Verizon 4G LTE Network Extender with firmware version 0.4.038.2131 and GA4.38.
What kind of attack can exploit CVE-2022-29729?
CVE-2022-29729 can be exploited by unauthenticated attackers via the webUI login page, allowing unauthorized access to the device.
Is there a patch available for CVE-2022-29729?
Currently, there is no official patch released for CVE-2022-29729, but changing default passwords is recommended as a preventive measure.