CVE-2019-12941

CRITICAL

AutoPi Wi-Fi/NB and 4G/LTE Firmware < 2019-10-15 - Unauthenticated Brute-Force Attack via WiFi Password Derivation

Title source: llm
STIX 2.1

Description

AutoPi Wi-Fi/NB and 4G/LTE devices before 2019-10-15 allows an attacker to perform a brute-force attack or dictionary attack to gain access to the WiFi network, which provides root access to the device. The default WiFi password and WiFi SSID are derived from the same hash function output (input is only 8 characters), which allows an attacker to deduce the WiFi password from the WiFi SSID.

References (3)

Core 3

Scores

CVSS v3 9.8
EPSS 0.0238
EPSS Percentile 81.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-307
Status published
Products (2)
autopi/4g\/lte_firmware < 2019-10-15
autopi/wi-fi\/nb_firmware < 2019-10-15
Published Oct 14, 2019
Tracked Since Feb 18, 2026