Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2009-5149 Details

Description

Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 have predictable technician passwords, which makes it easier for remote attackers to obtain access via the web management interface, related to a "password of the day" issue.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-255Credentials Management Errors[email protected]

Affected Products

ProductVersions
arris na model 862 gw mono firmware
ts070593c_073013
ts0703128_100611
ts0703135_112211
ts0705125_062314
ts0705125d_031115

CPE

  • cpe:2.3:o:arris:na_model_862_gw_mono_firmware:ts070593c_073013:*:*:*:*:*:*:*
  • cpe:2.3:o:arris:na_model_862_gw_mono_firmware:ts0703128_100611:*:*:*:*:*:*:*
  • cpe:2.3:o:arris:na_model_862_gw_mono_firmware:ts0703135_112211:*:*:*:*:*:*:*
  • cpe:2.3:o:arris:na_model_862_gw_mono_firmware:ts0705125_062314:*:*:*:*:*:*:*
  • cpe:2.3:o:arris:na_model_862_gw_mono_firmware:ts0705125d_031115:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
arris dg860a
All versions

CPE

  • cpe:2.3:h:arris:dg860a:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
arris tg862a
All versions

CPE

  • cpe:2.3:h:arris:tg862a:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
arris tg862g
All versions

CPE

  • cpe:2.3:h:arris:tg862g:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2009-5149
NVD Published Date:
Nov 21, 2015
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2009-5149 Details - Not Deferred