CVE-2020-15023
Askey AP5100W devices through AP5100W_Dual_SIG_1.01.097 are affected by WPS PIN offline brute-force cracking. This arises because of issues with the random number selection for the Diffie-Hellman exchange. By capturing an attempted (and even failed) WPS authentication attempt, it is possible to brute force the overall authentication exchange. This allows an attacker to obtain the recovered WPS PIN in minutes or even seconds, and eventually obtain the Wi-Fi PSK key, gaining access to the Wi=Fi network.
Published:Dec 11, 2020
Last Modified:Nov 21, 2024
EPS:Dec 11, 2020
EPSS Score:0.00414
CVSS Score:5.9
Affected Products
Vendor
Product
Action
Vendor
Askey
Product
Ap5100w
Askey
Ap5100w
Vendor
Askey
Product
Ap5100w Firmware
Askey
Ap5100w Firmware
Exploits
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
References
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
