Smartcom Ralink CPE/WiFi Routers Weak Default WiFi Password Vulnerability
Vulnerability
A vulnerability exists in Smartcom Bulgaria AD Smartcom Ralink CPE/WiFi routers, specifically the SAM-4G1G-TT-W-VC and SAM-4F1F-TT-W-A1 models. The issue arises from a weak default WiFi password generation algorithm, which allows remote attackers to obtain sensitive information. The vulnerability exploits the fact that the serial number, used in password generation, can be easily derived from the router's BSSID.
Impact
Exploitation of this vulnerability allows for unrestricted access to the user's internal network, access to the router's local administrative interface using hardcoded credentials, decryption of WiFi traffic, and the possibility of conducting active man-in-the-middle attacks against clients outside the access point's coverage.
Reproduction
The vulnerability can be reproduced by capturing the BSSID of the targeted router. Once the BSSID is obtained, the default WiFi password can be generated using a simple Bash command that replicates the router's password generation algorithm. This command reads the BSSID, appends it to a predefined string, and then computes an MD5 hash, from which the first eight characters are extracted to form the WiFi password.
Remediation
Users are advised to change the default WiFi password and ESSID. This can be done through the device's configuration panel, an ISP-provided interface, or by contacting ISP support for assistance.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
