CVE-2019-9555: Sagemcom F@st 5260 Firmware

Medium severity, CVSS 5.3. EPSS: 1.1% chance of exploitation in the next 30 days.

Sagemcom F@st 5260 routers using firmware version 0.4.39, in WPA mode, default to using a PSK that is generated from a 2-part wordlist of known values and a nonce with insufficient entropy. The number of possible PSKs is about 1.78 billion, which is too small.

Affected products

  • Sagemcom F@st 5260 Firmware: version 0.4.39 only

Published 2019-03-05. Last modified 2026-06-17.