CVE-2024-25729: Arris SBG6580

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Arris SBG6580 devices have predictable default WPA2 security passwords that could lead to unauthorized remote access. (They use the first 6 characters of the SSID and the last 6 characters of the BSSID, decrementing the last octet.)

Affected products

  • Arris SBG6580: any version

Published 2024-03-08. Last modified 2026-06-17.