Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-23726

Опубликовано: 21 янв. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:ubeeinteractive:ddw365_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ubeeinteractive:ddw365:-:*:*:*:*:*:*:*

EPSS

Процентиль: 72%
0.00703
Низкий

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798

Связанные уязвимости

CVSS3: 8.8
github
около 2 лет назад

Ubee DDW365 XCNDDW365 and DDW366 XCNDXW3WB devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.

EPSS

Процентиль: 72%
0.00703
Низкий

8.8 High

CVSS3

Дефекты

CWE-798
CWE-798