CVE-2014-8656 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 10.9% (pctl 96)
Patch early
A public exploit exists.
Description
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers to obtain access to certain sensitive information via unspecified vectors.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 10.86% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-255 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-11-06 |
| Last modified | 2026-06-17 |
Affected (3)
| Vendor | Product |
|---|---|
| compal broadband networks | cg6640e wireless gateway |
| compal broadband networks | ch664oe wireless gateway |
| compal broadband networks | firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities | 2014-10-27 |
References
- http://osvdb.org/show/osvdb/113836
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html
- http://www.exploit-db.com/exploits/35075
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php
- http://osvdb.org/show/osvdb/113836
- http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html
- http://www.exploit-db.com/exploits/35075
- http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php
→ the Explorer · watch your stack · NVD