CVE-2024-25730

Hitron CODA-4582 and CODA-4589 devices have default PSKs that are generated from 5-digit hex values concatenated with a "Hitron" substring, resulting in insufficient entropy (only about one million possibilities).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hitrontech:coda-4582u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:coda-4582u:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:hitrontech:coda-4589_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:coda-4589:-:*:*:*:*:*:*:*

History

05 May 2025, 19:16

Type Values Removed Values Added
First Time Hitrontech coda-4589 Firmware
Hitrontech coda-4582u
Hitrontech coda-4589
Hitrontech coda-4582u Firmware
Hitrontech
References () https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730 - () https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730 - Third Party Advisory
References () https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp - () https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp - Product
References () https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp - () https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp - Product
References () https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp - () https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp - Product
References () https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp - () https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp - Product
References () https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp - () https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp - Product
References () https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp - () https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp - Product
CPE cpe:2.3:h:hitrontech:coda-4582u:-:*:*:*:*:*:*:*
cpe:2.3:o:hitrontech:coda-4589_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:hitrontech:coda-4582u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:hitrontech:coda-4589:-:*:*:*:*:*:*:*

21 Nov 2024, 09:01

Type Values Removed Values Added
References () https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730 - () https://github.com/actuator/cve/blob/main/Hitron/CVE-2024-25730 -
References () https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp - () https://i.ebayimg.com/images/g/I-8AAOSwGE9lsGwI/s-l1600.webp -
References () https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp - () https://i.ebayimg.com/images/g/MwMAAOSwjTFk3kpd/s-l1600.webp -
References () https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp - () https://i.ebayimg.com/images/g/VDcAAOSwlodlSuz4/s-l1600.webp -
References () https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp - () https://i.ebayimg.com/images/g/XaAAAOSwvMNkuESk/s-l1600.webp -
References () https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp - () https://i.ebayimg.com/images/g/hzUAAOSwUwVllGMZ/s-l1600.webp -
References () https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp - () https://i.ebayimg.com/images/g/qK8AAOSwbr9lq3PJ/s-l1600.webp -

16 Aug 2024, 18:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) Los dispositivos Hitron CODA-4582 y CODA-4589 tienen PSK predeterminados que se generan a partir de valores hexadecimales de 5 dígitos concatenados con una subcadena "Hitron", lo que resulta en una entropía insuficiente (sólo alrededor de un millón de posibilidades).
CWE CWE-331

23 Feb 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-23 22:15

Updated : 2025-05-05 19:16


NVD link : CVE-2024-25730

Mitre link : CVE-2024-25730

CVE.ORG link : CVE-2024-25730


JSON object : View

Products Affected

hitrontech

  • coda-4582u_firmware
  • coda-4589
  • coda-4589_firmware
  • coda-4582u
CWE
CWE-331

Insufficient Entropy