PT-2021-23802 · Victure · Victure Wr1200

Published

2021-11-30

·

Updated

2021-12-03

·

CVE-2021-43282

CVSS v3.1

6.5

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Victure WR1200 devices through 1.0.3
Description An issue was discovered where the default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device's default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.
Recommendations For Victure WR1200 devices through 1.0.3, change the default Wi-Fi password to a unique and strong password to prevent unauthorized access. Consider disabling the default Wi-Fi network until a secure password is set. Restrict access to the Wi-Fi network to minimize the risk of exploitation.

Exploit

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43282

Affected Products

Victure Wr1200