CVE-2025-67114
Received Received - Intake
Deterministic Credential Leak in Sercomm SCE4255W Enables Authentication Bypass

Publication date: 2026-03-19

Last updated on: 2026-03-24

Assigner: MITRE

Description
Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware before DG3934v3@2308041842 allows remote attackers to derive valid administrative/root credentials from the device's MAC address, enabling authentication bypass and full device access.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-19
Last Modified
2026-03-24
Generated
2026-06-16
AI Q&A
2026-03-19
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
sercomm sce4255w *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1391 The product uses weak credentials (such as a default key or hard-coded password) that can be calculated, derived, reused, or guessed by an attacker.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves the use of a deterministic credential generation algorithm in the /ftl/bin/calc_f2 component of the Small Cell Sercomm SCE4255W firmware. Because the credentials are generated deterministically based on the device's MAC address, remote attackers can derive valid administrative or root credentials simply by knowing the MAC address.

This allows attackers to bypass authentication mechanisms and gain full access to the device.

Impact Analysis

An attacker who exploits this vulnerability can gain unauthorized administrative or root access to the affected device.

  • Full device control, including configuration changes and potential disruption of services.
  • Potential exposure of sensitive data stored or processed by the device.
  • Use of the compromised device as a foothold for further attacks within the network.
Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-67114. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart