CVE-2024-23726

U

bee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:ubeeinteractive:ddw365_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:ubeeinteractive:ddw365:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://github.com/actuator/cve/blob/main/Ubee/CWE-1392.md - Third Party Advisory () https://github.com/actuator/cve/blob/main/Ubee/CWE-1392.md - Third Party Advisory

Information

Published : 2024-01-21 04:15

Updated : 2025-05-30 15:15


NVD link : CVE-2024-23726

Mitre link : CVE-2024-23726

CVE.ORG link : CVE-2024-23726


JSON object : View

CWE
CWE-798

Use of Hard-coded Credentials