CVE-2024-23726
Ubeeinteractive
CVE-2024-23726: Ubee DDW365 devices suffer from a vulnerability due to predictable default WPA2 PSKs. This allows unauthorized remote access by attackers near the Wi-Fi network. By observing a beacon frame, the attacker can derive the default WPA2-PSK using the SSID and BSSID, making it easy to compromise the network. Given the CVSS score of 8.8, this is a high-severity vulnerability, but SOCRadar's SVRS of 42 suggests the immediate risk isn't critical, though still requires patching. If exploited, the vulnerability allows a remote attacker to gain complete access to the network, potentially leading to data theft or further malicious activities. The predictable PSK generation is a significant security flaw, making these devices vulnerable to compromise.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.