IoT & Hardware
Authentication & Access Bypass
Wi-Fi De-Authentication of Connected Clients in Waveshare RS232/485 TO WIFI ETH (B)
Prevents legitimate Wi-Fi access and disrupts data relay between serial and Ethernet interfaces.
.png)
Overview
Wi-Fi De-Authentication of Connected Clients:
Absence of 802.11w or Management Frame Protection (MFP) allows unauthenticated attackers to broadcast crafted deauthentication and disassociation frames.
The Wi-Fi router is vulnerable to de-authentication attacks due to the absence of Management Frame Protection (MFP or 802.11w), allowing forged deauthentication and disassociation frames to be broadcast without authentication or encryption.
This exposes the network to unauthorized disruptions, as attackers can disconnect clients using tools like aireplay-ng, undermining the availability and reliability of the Wi-Fi connection. The vulnerability persists despite the use of WPA2-PSK AES encryption for data frames, as management frames remain unprotected.
Vulnerability details
Wi-Fi De-Authentication of Connected Clients: Absence of 802.11w or Management Frame Protection (MFP) allows unauthenticated attackers to broadcast crafted deauthentication and disassociation frames.
What an attacker can do
Prevents legitimate Wi-Fi access and disrupts data relay between serial and Ethernet interfaces.
Disclosure timeline
2025-09-16 Initial report sent via Waveshare support portal with full disclosure report.
2025-09-23 Vendor acknowledged receipt.
2025-09-23 Researcher requested remediation timeline, CVD process, and CVE coordination details.
2025-09-24 Vendor replied: "Information received; feedback will be taken into account in future research."
2025-09-24 Researcher requested confirmation on CVD process and timeline.
2025-09-27 Vendor responded: "No specific timeline can be provided; security feedback will be considered in subsequent products."
2025-09-27 Researcher informed
References
2026-06-17 (NVD record)
Credits
Ranit Pradhan and Abhishek Pandey – Payatu Security Consulting Pvt. Ltd.
















