CVE-2024-23726

HIGH
Published Jan 21, 2024 Modified May 30, 2025 CWE-798

Description

Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit.

Is your site exposed to CVE-2024-23726?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weakness Type (CWE)

CWE-798 CWE-798

Affected Products

Vendor Product
ubeeinteractive ddw365_firmware
ubeeinteractive ddw365

References

Frequently Asked Questions

What is CVE-2024-23726? +
Ubee DDW365 XCNDDW365 devices have predictable default WPA2 PSKs that could lead to unauthorized remote access. A remote attacker (in proximity to a Wi-Fi network) can derive the default WPA2-PSK value by observing a beacon frame. A PSK is generated by using the first six characters of the SSID and the last six of the BSSID, decrementing the last digit. It has a CVSS v3.1 base score of 8.8 (HIGH).
How severe is CVE-2024-23726? +
CVE-2024-23726 has a CVSS v3.1 score of 8.8 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2024-23726? +
CVE-2024-23726 affects products from ubeeinteractive, specifically: ddw365, ddw365_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2024-23726? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2024-23726 — free, no signup required.