used, these shall be generated with a mechanism that reduces the risk of automated attacks against a class or type of device. 1. How the pre-installed passwords are generated for each device and what is done to ensure that the pre-installed passwords are sufficiently random. 2. Where and when are the passwords generated (e.g. offdevice and provisioned onto the device subsequently, or generated upon device's initial boot-up sequence)? 3. How are the randomised passwords generated? Was a random function or a cryptographically secure pseudo random number generator used? Are the randomised passwords based on any device information (MAC address, etc.)? Minimally, the following are required for pre-installed passwords: 1. Passwords with incremental counters ("password1", "password2") are not allowed. 2. Pre-installed passwords must CLS Publication #2 | Page 22 of 49

Select target paragraph3