CVE-2020-9476 describes a critical information disclosure vulnerability in ARRIS TG1692A devices, affecting both the hardware and its firmware. Attackers can remotely extract the administrator login credentials by simply accessing the /login page and performing a Base64 decode. This vulnerability carries a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low complexity, and complete confidentiality impact, allowing unauthorized access to the device. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the ease of exploitation presents a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.1.103de2CPE matchmatch criteria | cpe:2.3:o:commscope:arris_tg1692a_firmware:9.1.103de2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.