CVE-2025-67114
CRITICALSmall Cell Sercomm SCE4255W <DG3934v3@2308041842 - Auth Bypass
Title source: llmDescription
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypass and full device access.
References (3)
Core 3
Scores
CVSS v3
9.8
EPSS
0.0052
EPSS Percentile
39.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-1391
Status
published
Published
Mar 19, 2026
Tracked Since
Mar 19, 2026