CVE detail
CVE-2023-40038 — CVE-2023-40038
Published 2023-12-27 · Modified 2026-06-17 · Vendor arris · Product dg860a_firmware · Source nvd
HIGH
severity
CVSS-derived band
0.0032
EPSS probability
exploitation probability, 30d
25.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References