CVE-2022-28376
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Verizon 5G Home LVSKIHP outside devices through 2022-02-15 allow anyone (knowing the device's serial number) to access a CPE admin website, e.g., at the 10.0.0.1 IP address. The password (for the verizon username) is calculated by concatenating the serial number and the model (i.e., the LVSKIHP string), running the sha256sum program, and extracting the first seven characters concatenated with the last seven characters of that SHA-256 value.
Los dispositivos exteriores LVSKIHP de Verizon 5G Home hasta el 2022-02-15 permiten a cualquiera (conociendo el número de serie del dispositivo) acceder a un sitio web de administración del CPE, por ejemplo, en la dirección IP 10.0.0.1. La contraseña (para el nombre de usuario de Verizon) se calcula concatenando el número de serie y el modelo (es decir, la cadena LVSKIHP), ejecutando el programa sha256sum y extrayendo los siete primeros caracteres concatenados con los siete últimos de ese valor SHA-256
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-04-03 CVE Reserved
- 2022-04-03 CVE Published
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- 2025-04-13 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://www.reddit.com/r/verizon/comments/sstq4c/5g_home_internet_dropping_out/hx3ir0s | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/JousterL/SecWriteups/blob/main/Verizon%20LVSKIHP%205G%20Modem/readme.md | 2024-08-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Verizon Search vendor "Verizon" | Lvskihp Firmware Search vendor "Verizon" for product "Lvskihp Firmware" | <= 2022-02-15 Search vendor "Verizon" for product "Lvskihp Firmware" and version " <= 2022-02-15" | - |
Affected
| in | Verizon Search vendor "Verizon" | Lvskihp Search vendor "Verizon" for product "Lvskihp" | - | - |
Safe
|