CVE Feed

    Dashboard / CVE / CVE-2019-12941

    CVE-2019-12941

    AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash function output (input is only 8 characters), which allows an attacker to deduce the WiFi password from the WiFi SSID.

    Published:Oct 14, 2019
    Last Modified:Nov 21, 2024
    EPS:Oct 14, 2019
    EPSS Score:0.00448
    CVSS Score:9.8

    Affected Products

    Vendor
    Autopi
    Product
    4g\/lte
    Vendor
    Autopi
    Product
    4g\/lte Firmware
    Vendor
    Autopi
    Product
    Wi-fi\/nb
    Vendor
    Autopi
    Product
    Wi-fi\/nb Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High