PT-2021-23802 · Victure · Victure Wr1200
Published
2021-11-30
·
Updated
2021-12-03
·
CVE-2021-43282
CVSS v3.1
6.5
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Victure WR1200 devices through 1.0.3
Description
An issue was discovered where the default Wi-Fi WPA2 key is advertised to anyone within Wi-Fi range through the router's MAC address. The device's default Wi-Fi password corresponds to the last 4 bytes of the MAC address of its 2.4 GHz network interface controller (NIC). An attacker within scanning range of the Wi-Fi network can thus scan for Wi-Fi networks to obtain the default key.
Recommendations
For Victure WR1200 devices through 1.0.3, change the default Wi-Fi password to a unique and strong password to prevent unauthorized access. Consider disabling the default Wi-Fi network until a secure password is set. Restrict access to the Wi-Fi network to minimize the risk of exploitation.
Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Victure Wr1200