PT-2026-26319 · Sercomm+1 · Sercomm Sce4255W+1
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2025-67114
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Small Cell Sercomm SCE4255W (FreedomFi Englewood) versions prior to DG3934v3@2308041842
Description
A deterministic credential generation algorithm in
/ftl/bin/calc f2 allows remote attackers to derive valid administrative and root credentials from the device's MAC address. This enables authentication bypass and full device access. The affected component is the calc f2 function located at the /ftl/bin/ path.Recommendations
Update to version DG3934v3@2308041842 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freedomfi Englewood
Sercomm Sce4255W