CVE-2014-8656
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers to obtain access to certain sensitive information via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 10.85% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- compal broadband networks/firmware · compal broadband networks/cg6640e wireless gateway · compal broadband networks/ch664oe wireless gateway
- Source
- cve@mitre.org
References
- http://osvdb.org/show/osvdb/113836
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.htmlExploit
- http://www.exploit-db.com/exploits/35075Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.phpExploit
- http://osvdb.org/show/osvdb/113836
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.htmlExploit
- http://www.exploit-db.com/exploits/35075Exploit
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.phpExploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.