CVE-2015-0558 describes a vulnerability in the ADB P.DGA4001N router, and potentially other models, where the WPA key is predictably generated using a static string and the device's MAC address. This design flaw, categorized as CWE-311 (Improper Storage of Sensitive Information), carries a CVSS v3.1 score of 5.3 (Medium), indicating a low-complexity network attack that could lead to limited integrity impact. While there is no evidence of active exploitation, public exploit code, or Metasploit modules, the vulnerability has garnered some community discussion regarding reverse-engineering the key generation algorithm. Its EPSS and FAUCET scores suggest a low likelihood of exploitation and overall risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
pdg_tef_sp_4.06l.6CPE matchmatch criteria | cpe:2.3:o:adbglobal:p.dga4001n_firmware:pdg_tef_sp_4.06l.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.