Flaw affecting 1B+ Wi-Fi-enabled devices allows attackers to decrypt wireless network packets - Help Net Security

Flaw affecting 1B+ Wi-Fi-enabled devices allows attackers to decrypt wireless network packets - Help Net Security

ESET researchers have discovered Kr00k (CVE-2019-15126), a previously unknown vulnerability in Wi-Fi chips used in many client devices, Wi-Fi access points and routers.



Kr00k is a vulnerability that causes the network communication of an affected device to be encrypted with an all-zero encryption key. In a successful attack, this allows an adversary to decrypt wireless network packets.


About CVE-2019-15126


The discovery of Kr00k follows previous ESET research into the Amazon Echo being vulnerable to KRACKs (Key Reinstallation Attacks). Kr00k is related to KRACK, but is also fundamentally different.


During the investigation into KRACK, ESET researchers identified Kr00k as one of the causes behind the “reinstallation” of an all-zero encryption key observed in tests for KRACK attacks. Subsequent to their research, most major device manu ..

Support the originator by clicking the read the rest link below.