ARRIS TG1692A devices allow remote attackers to discover the administrator login name and password by reading the /login page and performing base64 decoding.
References
Link | Resource |
---|---|
https://medium.com/@rsantos_14778/info-disclosure-cve-2020-9476-494a08298c6b | Exploit Third Party Advisory |
https://arris.secure.force.com/consumers/ConsumerProductSupport | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-03-04 11:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-9476
Mitre link : CVE-2020-9476
JSON object : View
CWE
CWE-326
Inadequate Encryption Strength
Products Affected
commscope
- arris_tg1692a_firmware
- arris_tg1692a