CVE-2025-67114
CRITICALSmall Cell Sercomm SCE4255W <DG3934v3@2308041842 - Auth Bypass
Title source: llmDescription
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypass and full device access.
Scores
CVSS v3
9.8
EPSS
0.0046
EPSS Percentile
64.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1391
Status
published
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026