PT-2024-35984 · Victure · Victure Rx1800 Wifi 6 Router

Edward Warren

·

Published

2024-12-02

·

Updated

2024-12-03

·

CVE-2024-53941

CVSS v3.1
8.8
VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

Victure RX1800 WiFi 6 Router version EN V1.0.0 r12 110933

Description:

A problem was discovered in Victure RX1800 WiFi 6 Router devices, where a remote attacker in proximity to a Wi-Fi network can derive the default Wi-Fi PSK value via the last 4 octets of the BSSID.

Recommendations:

For version EN V1.0.0 r12 110933, consider changing the default Wi-Fi PSK value to a unique and strong password to minimize the risk of exploitation.

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-53941

Affected Products

Victure Rx1800 Wifi 6 Router