CVE-2013-4877: Verizon Wireless Network Extender
Low severity, CVSS 2.6. EPSS: 0.8% chance of exploitation in the next 30 days.
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and conduct cloning attacks, by sniffing the network for registration packets.
Affected products
- Verizon Wireless Network Extender: version scs-2u01 only; version scs-26uc4 only
Published 2013-07-18. Last modified 2026-06-16.