{
    "id": "CVE-2014-8656",
    "published": "2014-11-06 15:55:10",
    "last_modified": "2026-06-17 00:17:06",
    "cvss_score": "10.0",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
    "cwe": "CWE-255",
    "description": "The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a default password of (1) admin for the admin account and (2) compalbn for the root account, which makes it easier for remote attackers to obtain access to certain sensitive information via unspecified vectors.",
    "epss_score": "0.10855",
    "epss_percentile": "0.95738",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-03 18:17:14",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "compal_broadband_networks",
            "product": "cg6640e_wireless_gateway"
        },
        {
            "vendor": "compal_broadband_networks",
            "product": "ch664oe_wireless_gateway"
        },
        {
            "vendor": "compal_broadband_networks",
            "product": "firmware"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "35075",
            "title": "CBN CH6640E/CG6640E Wireless Gateway Series - Multiple Vulnerabilities",
            "date": "2014-10-27",
            "url": "https://www.exploit-db.com/exploits/35075"
        }
    ],
    "refs_list": [
        "http://osvdb.org/show/osvdb/113836",
        "http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html",
        "http://www.exploit-db.com/exploits/35075",
        "http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php",
        "http://osvdb.org/show/osvdb/113836",
        "http://packetstormsecurity.com/files/128860/CBN-CH6640E-CG6640E-Wireless-Gateway-XSS-CSRF-DoS-Disclosure.html",
        "http://www.exploit-db.com/exploits/35075",
        "http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5203.php"
    ]
}