Wireless Security
Audit Wi-Fi (802.11), Bluetooth Classic + BLE, sub-GHz RF and NFC/RFID surfaces against the Wireless Security Baseline (NIST SP 800-153 / 121 R2 / 97 + IEEE 802.11i). 18 detection rules + 24 baseline controls.
4
WEP / WPS / hardcoded PSK
3
PINs, SSP, discoverable
5
Just Works / LESC / GATT
2
Fixed-code / LoRa / ISM
2
MIFARE / UID-only auth
3
Zigbee / MQTT / CoAP
19
across all surfaces
71%
Wireless Security Baseline
BLE Just Works pairing
MITM during pairing — promote to Numeric ComparisonDetection Rules (18)
Critical Severity
WEP encryption referenced
Hardcoded SSID + PSK pair
Default / weak pairing PIN
Hardcoded passkey / bonding key
Default Zigbee TC link key
High / Medium Severity
WPA/TKIP encryption referenced
WPS enabled
Open / unauthenticated network
Legacy pairing (no SSP)
Permanently discoverable
Just Works pairing (no MITM protection)
LE Secure Connections disabled
GATT characteristic without enc/auth
Fixed-code RF transmission
Hardcoded ISM-band frequency
LoRa / sub-GHz without encryption
MIFARE Classic in use
Authorisation by tag UID only
MQTT over plain TCP (no TLS)
CoAP without DTLS
| Code | Title | Surface | Default Severity | Status |
|---|---|---|---|---|
WIFI.01 |
WEP and WPA/TKIP must not be used | Wi-Fi |
Critical |
Passed |
WIFI.02 |
WPA3-SAE or WPA3-Enterprise required | Wi-Fi |
High |
Passed |
WIFI.03 |
WPS must be disabled on all access points | Wi-Fi |
High |
Passed |
WIFI.04 |
SSIDs and PSKs must not be hardcoded | Wi-Fi |
Critical |
Violated |
WIFI.05 |
Open / unauthenticated SSIDs prohibited | Wi-Fi |
High |
Passed |
WIFI.06 |
Enterprise SSIDs must use 802.1X | Wi-Fi |
Medium |
Partial |
WIFI.07 |
WIDS/WIPS coverage in regulated env | Wi-Fi |
Medium |
Partial |
BT.01 |
Default / weak pairing PINs prohibited | Bluetooth |
Critical |
Passed |
BT.02 |
Secure Simple Pairing with MITM required | Bluetooth |
High |
Violated |
BT.03 |
BLE LE Secure Connections must be enabled | BLE |
High |
Violated |
BT.04 |
Just Works prohibited on sensitive chars | BLE |
High |
Violated |
BT.05 |
GATT must require encryption + auth | BLE |
Medium |
Partial |
BT.06 |
Per-device passkey / bonding key | BLE |
Critical |
Passed |
BT.07 |
Discoverable mode limited to short window | Bluetooth |
Medium |
Passed |
BT.08 |
Bluetooth 5.2+ Secure Connections Only | Bluetooth |
Medium |
Passed |
RF.01 |
Rolling-code or AES-CTR (no fixed-code) | RF |
High |
Passed |
RF.02 |
RF payloads cryptographically authenticated | RF |
High |
Passed |
RF.03 |
LoRa / sub-GHz with LoRaWAN OTAA + AES | RF |
High |
Passed |
NFC.01 |
Migrate from MIFARE Classic to DESFire EV2/EV3 | NFC |
High |
Violated |
NFC.02 |
No authorisation by tag UID alone | NFC |
High |
Passed |
IOT.01 |
Default Zigbee TC link key prohibited | IoT |
Critical |
Passed |
IOT.02 |
MQTT must run over TLS (port 8883) | IoT |
High |
Violated |
IOT.03 |
CoAP must run over DTLS 1.2+ | IoT |
Medium |
Partial |
IOT.04 |
Per-device unique creds at manufacturing | IoT |
High |
Passed |
Findings by surface
Severity distribution