cve/2024/CVE-2024-23726.md
2024-05-25 21:48:12 +02:00

849 B

CVE-2024-23726

Description

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.

POC

Reference

No PoCs from references.

Github