Information leak in Compaq WL310, and the Orinoco Residential Gateway access point it is based on, uses a system identification string as a default SNMP read/write community string, which allows remote attackers to obtain and modify sensitive configuration information by querying for the identification string.
📦
orinoco_rg-1000
Vendor: lucent
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
0
Remote Access
Total CVEs
1
Total Indexed
Avg. EPSS
4.37%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
6.4
CVSS
CVE-2002-0812
Exploit Found
Severity: MEDIUM
7.5
CVSS
Orinoco RG-1000 wireless Residential Gateway uses the last 5 digits of the 'Network Name' or SSID as the default Wired Equivalent Privacy (WEP) encryption key. Since the SSID occurs in the clear during communications, a remote attacker could determine the WEP key and decrypt RG-1000 traffic.
Severity: HIGH