CVE-2023-40038
Description
Arris DG860A and DG1670A routers use predictable default WPA2 PSKs derived from SSID and BSSID, enabling unauthorized network access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Arris DG860A and DG1670A routers use predictable default WPA2 PSKs derived from SSID and BSSID, enabling unauthorized network access.
Vulnerability
The Arris DG860A and DG1670A devices generate their default WPA2 Pre-Shared Key (PSK) using a predictable algorithm: the first 6 characters of the SSID concatenated with the last 6 characters of the BSSID, then decrementing the last digit by one [1]. This affects all units with factory-default wireless settings. No firmware version is specified in the available reference, but the vulnerability applies to both models as shipped.
Exploitation
An attacker within Wi-Fi range can passively capture the SSID and BSSID from beacon frames broadcast by the device. Using the known algorithm, the attacker computes the PSK and authenticates to the wireless network without any additional credentials or user interaction [1]. No prior access or authentication is required.
Impact
Successful exploitation grants the attacker full access to the victim's Wi-Fi network. This can lead to interception of network traffic, compromise of connected devices, and further attacks on internal resources. The attacker gains the same level of network access as any legitimate user [1].
Mitigation
No official fix or firmware update has been disclosed in the available reference [1]. Users are advised to manually change the default WPA2 passphrase to a strong, random value. If the device is no longer supported by the vendor, replacement with a patched model is recommended.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Arris/DG860A and DG1670A devicesdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2News mentions
0No linked articles in our index yet.