CVE-2024-25729: High severity Arris SBG6580 vulnerability
Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last octet.)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25729?
CVE-2024-25729 is considered a medium severity vulnerability due to its potential for unauthorized remote access.
How do I fix CVE-2024-25729?
To fix CVE-2024-25729, change the default WPA2 security password to a custom password that is not based on the SSID or BSSID.
Which devices are affected by CVE-2024-25729?
CVE-2024-25729 affects Arris SBG6580 devices due to predictable default WPA2 security passwords.
What are the risks associated with CVE-2024-25729?
The risks associated with CVE-2024-25729 include unauthorized access to the network, which can lead to data breaches and compromised devices.
How does CVE-2024-25729 exploit the default WPA2 passwords?
CVE-2024-25729 exploits the predictable generation of default WPA2 passwords using the first 6 characters of the SSID and the last 6 characters of the BSSID, making them easily guessable.