CVE-2020-15023 describes a vulnerability in Askey AP5100W devices, specifically firmware versions through AP5100W_Dual_SIG_1.01.097. This flaw allows for offline brute-force cracking of the WPS PIN due to insufficient randomness in the Diffie-Hellman exchange. The vulnerability carries a CVSS score of 5.9 (Medium) and is rated as AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N. An attacker can exploit this remotely with high attack complexity to gain full access to the Wi-Fi network by recovering the WPS PIN and subsequently the PSK key. There is currently no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.01.097CPE matchmatch criteria | cpe:2.3:o:askey:ap5100w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.