CVE-2023-40038: High severity arris dg860a firmware vulnerability
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-40038?
CVE-2023-40038 is considered a medium severity vulnerability due to the potential for unauthorized remote access.
What devices are affected by CVE-2023-40038?
CVE-2023-40038 affects Arris DG860A and DG1670A devices, specifically those with predictable default WPA2 PSKs.
How do I fix CVE-2023-40038?
To mitigate CVE-2023-40038, users should change the default WPA2 PSK to a stronger, custom password that does not follow the predictable pattern.
What risks are associated with CVE-2023-40038?
The risks associated with CVE-2023-40038 include unauthorized remote access to the network, potentially allowing attackers to intercept or manipulate network traffic.
How can I verify if my Arris device is vulnerable to CVE-2023-40038?
You can verify if your Arris device is vulnerable to CVE-2023-40038 by checking if it has the default WPA2 PSK setup as described in the vulnerability details.