New paper about wireless technologies vulnerability (BREAK)
According to a news from Northeastern University, a paper has been published regarding an intrinsic wireless standar vulnerability that can be exploited for gaining access to wireless networks.
Five italian security researchers are signing the paper.
link to the article
https://news.northeastern.edu/2025/01/09/wifi-security-vulnerability-research/
link to the paper
https://mentis.info/wp-content/uploads/2025/01/INFOCOM2025_BREAK_2025.pdf
According to the paper, in May the final verison will be presented at London IEEE INFOCOM
Seems that security issues even in 2025 won't have a BREAK. dmnd.
All Replies
-
Hi users,
The BREAK attack reveals a severe vulnerability in the Wi-Fi MU-MIMO protocol. The attacker eavesdrops on the MU-MIMO feedback from other STAs (which is transmitted in plaintext) and then crafts malicious feedback to manipulate the AP’s precoding, thereby reducing the overall network throughput.
Unfortunately, solving this vulnerability may require an update to the Wi-Fi standard itself. We have already reported our concern to our chipset vendor and will continue to monitor IEEE's countermeasures and fixes for this technical vulnerability.
0 -
In wifi communications this kind of vulerability is close to the Spectre-Meltdown event for CPUs.
I don't see Wifi8 coming so soon, without solving these kind of issue, and I'm waiting for a backward compatiblity-break for some features in the future.
0 -
Hi @mMontana ,
We are waiting for the chipset vendor to provide a solution before we can implement a fix.
By the way, could you explain what you mean by "a backward compatibility break"?
0 -
AFAIK, even latest 802.11be AP (WiFi7) can communicate with 802.11a network card, if the security protocols are managed/allowed on both sides.
How much time will it last? Not so much…
I'm especting some future release of wireless ethernet that will break this kind of backward compatibility Wifi4 is probably the second or the first most diffused standard among all devices but I won't bat that new AP in three years will support that protocol.
0 -
Hi @mMontana ,
Thank you for your feedback. We will continue to monitor and assess this vulnerability.
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 102 Nebula Status and Incidents
- 5.8K Security
- 305 USG FLEX H Series
- 283 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 255 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.7K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 77 Security Highlight