CVE-2019-15805

CRITICAL

CommScope ARRIS TR4400 - Auth Bypass

Title source: llm
STIX 2.1

Description

CommScope ARRIS TR4400 devices with firmware through A1.00.004-180301 are vulnerable to an authentication bypass to the administrative interface because they include the current base64 encoded password within http://192.168.1.1/login.html. Any user connected to the Wi-Fi can exploit this.

Scores

CVSS v3 9.8
EPSS 0.0119
EPSS Percentile 63.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-326
Status published
Products (1)
commscope/tr4400_firmware < a1.00.004-180301
Published Aug 29, 2019
Tracked Since Feb 18, 2026