CVE-2015-4624 describes a critical vulnerability in Hak5 WiFi Pineapple versions 2.0 through 2.3, stemming from the use of predictable Cross-Site Request Forgery (CSRF) tokens. With a CVSS score of 7.5 (HIGH), this flaw allows an attacker on the same network to execute arbitrary commands with high impact on confidentiality, integrity, and availability, requiring no user interaction. While not listed on the KEV catalog or Hot List, Metasploit modules exist for preconfiguration command injection, indicating readily available exploit code. Despite its high risk, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:o:hak5:wi-fi_pineapple_firmware:2.0:*:*:*:*:*:*:* | ||
2.1CPE matchmatch criteria | cpe:2.3:o:hak5:wi-fi_pineapple_firmware:2.1:*:*:*:*:*:*:* | ||
2.2CPE matchmatch criteria | cpe:2.3:o:hak5:wi-fi_pineapple_firmware:2.2:*:*:*:*:*:*:* | ||
2.3CPE matchmatch criteria | cpe:2.3:o:hak5:wi-fi_pineapple_firmware:2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.