PT-2022-18985 · Verizon · Verizon 5G Home

Published

2022-04-03

·

Updated

2023-08-08

·

CVE-2022-28376

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Verizon 5G Home LVSKIHP outside devices through 2022-02-15
Description The issue allows anyone with knowledge of the device's serial number to access a CPE admin website, for example, at the "10.0.0.1" IP address. The password for the verizon username is calculated by concatenating the serial number and the model (i.e., the LVSKIHP string), running the sha256sum program, and extracting the first seven characters concatenated with the last seven characters of that SHA-256 value.
Recommendations For Verizon 5G Home LVSKIHP outside devices through 2022-02-15, consider changing the default password calculation method to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the CPE admin website at the "10.0.0.1" IP address to minimize the risk of exploitation.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-28376

Affected Products

Verizon 5G Home