CVE-2023-40038: Arris DG1670A Firmware

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Arris DG860A and DG1670A devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last digit.)

Affected products

  • Arris DG1670A Firmware: version ts0901203b6_020420_16xx.gw_pc20_tw only
  • Arris DG860A Firmware: affected versions not specified

Published 2023-12-27. Last modified 2026-06-17.