CVE-2025-67114

Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypass and full device access.
Configurations

No configuration.

History

24 Mar 2026, 02:16

Type Values Removed Values Added
CWE CWE-1391
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) El uso de un algoritmo de generación de credenciales determinista en /ftl/bin/calc_f2 en el firmware del Small Cell Sercomm SCE4255W (FreedomFi Englewood) anterior a DG3934v3@2308041842 permite a atacantes remotos derivar credenciales administrativas/de root válidas de la dirección MAC del dispositivo, lo que permite la omisión de autenticación y el acceso completo al dispositivo.

19 Mar 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 18:16

Updated : 2026-06-17 09:57


NVD link : CVE-2025-67114

Mitre link : CVE-2025-67114

CVE.ORG link : CVE-2025-67114


JSON object : View

Products Affected

No product.

CWE
CWE-1391

Use of Weak Credentials