CVE-2024-23726
21.01.2024, 04:15
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.Enginsight
Vendor | Product | Version |
---|---|---|
ubeeinteractive | ddw365_firmware | - |
𝑥
= Vulnerable software versions