Title: Multiple Wireless Routers Predictable Default WEP/WPA Key Security Bypass Vulnerability
Severity: CRITICAL
Description:
Multiple wireless routers are prone to a vulnerability that can allow an attacker to predict their default WEP/WPA encryption keys.
Specifically, the algorithm to generate default SSID and encryption key values is based on a hash of the device's serial number.
Attackers can exploit this issue to bypass authentication to an affected device, which can allow them to completely compromise the device or to gain access to the private network.
The following products are vulnerable:
- Thomson SpeedTouch
- BT Home Hub
Affected Products:
- BT Home Hub
- Thomson SpeedTouch
References:
- BT: BT Home Hub
- GNUCITIZEN: Default key algorithm in Thomson and BT Home Hub routers
- Thomson Broadband: Thomson Homepage
