Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43282

Опубликовано: 30 нояб. 2021
Источник: nvd
CVSS3: 6.5
CVSS2: 3.3
EPSS Низкий

Описание

An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:govicture:wr1200_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.3 (включая)
cpe:2.3:h:govicture:wr1200:-:*:*:*:*:*:*:*

EPSS

Процентиль: 39%
0.00175
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-798

Связанные уязвимости

github
около 4 лет назад

An issue was discovered on Victure WR1200 devices through 1.0.3. The default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.

EPSS

Процентиль: 39%
0.00175
Низкий

6.5 Medium

CVSS3

3.3 Low

CVSS2

Дефекты

CWE-798