CVE-2015-5729
9.8
CRITICAL · CVSS 3.0 · EPSS 5% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a brute-force attack.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.97% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2017-03-23 |
| Last modified | 2026-06-17 |
Affected (21)
| Vendor | Product |
|---|---|
| samsung | m288ofw |
| samsung | m288ofw firmware |
| samsung | nt14u cn |
| samsung | nt14u eu |
| samsung | nt14u firmware |
| samsung | nt14u us |
| samsung | x10p eu |
| samsung | x10p firmware |
| samsung | x10p ibr |
| samsung | x10p us |
| samsung | x12 eu |
| samsung | x12 firmware |
| samsung | x12 us |
| samsung | x14h cn |
| samsung | x14h eu |
| samsung | x14h firmware |
| samsung | x14h us |
| samsung | x14j cn |
| samsung | x14j eu |
| samsung | x14j firmware |
| samsung | x14j us |
References
- http://kaoticoneutral.blogspot.com.ar/2015/12/samsung-smarttv-and-printers-weak.html
- http://packetstormsecurity.com/files/134976/Samsung-SoftAP-Weak-Password.html
- http://seclists.org/fulldisclosure/2015/Dec/79
- http://www.securityfocus.com/bid/79675
- http://www.securitytracker.com/id/1034503
- http://www.securitytracker.com/id/1034504
- http://kaoticoneutral.blogspot.com.ar/2015/12/samsung-smarttv-and-printers-weak.html
- http://packetstormsecurity.com/files/134976/Samsung-SoftAP-Weak-Password.html
- http://seclists.org/fulldisclosure/2015/Dec/79
- http://www.securityfocus.com/bid/79675
- http://www.securitytracker.com/id/1034503
- http://www.securitytracker.com/id/1034504
→ the Explorer · watch your stack · NVD