Wireless Security

Audit Wi-Fi (802.11), Bluetooth Classic + BLE, sub-GHz RF and NFC/RFID surfaces against the Wireless Security Baseline (NIST SP 800-153 / 121 R2 / 97 + IEEE 802.11i). 18 detection rules + 24 baseline controls.

Wi-Fi

4

WEP / WPS / hardcoded PSK

Bluetooth

3

PINs, SSP, discoverable

BLE

5

Just Works / LESC / GATT

RF

2

Fixed-code / LoRa / ISM

NFC

2

MIFARE / UID-only auth

IoT

3

Zigbee / MQTT / CoAP

Total wireless findings

19

across all surfaces


6 Critical
8 High
4 Medium
1 Low
Baseline coverage

71%

Wireless Security Baseline

17 / 24 controls passed
Top wireless threat

BLE Just Works pairing

MITM during pairing — promote to Numeric Comparison

Detection Rules (18)

Critical Severity

Wi-Fi

WEP encryption referenced

Critical
CWE-327 — Broken in minutes with Aircrack-ng
Wi-Fi

Hardcoded SSID + PSK pair

Critical
CWE-798 — Repo or built artefact owns the network
Bluetooth

Default / weak pairing PIN

Critical
CWE-521 — 0000 / 1234 / 123456 — trivial brute force
BLE

Hardcoded passkey / bonding key

Critical
CWE-798 — One key recovered = every shipped unit owned
IoT

Default Zigbee TC link key

Critical
CWE-1392 — ZigBeeAlliance09 — anyone joins the network

High / Medium Severity

Wi-Fi

WPA/TKIP encryption referenced

High
CWE-327 — Vulnerable to KRACK + dictionary attacks
Wi-Fi

WPS enabled

High
CWE-1391 — Brute-forceable in hours via Pixie Dust / Reaver
Wi-Fi

Open / unauthenticated network

High
CWE-319 — Plain traffic — passive sniffing trivial
Bluetooth

Legacy pairing (no SSP)

High
CWE-326 — Forces 4-digit PIN flow — offline crackable
Bluetooth

Permanently discoverable

Medium
CWE-200 — Fuel for inquiry-based attacks (BlueBorne)
BLE

Just Works pairing (no MITM protection)

High
CWE-300 — Pairing handshake interceptable in the middle
BLE

LE Secure Connections disabled

High
CWE-327 — Legacy LE pairing → passive eavesdropping
BLE

GATT characteristic without enc/auth

Medium
CWE-306 — PERMISSION_READ/WRITE without _ENCRYPTED variant
RF

Fixed-code RF transmission

High
CWE-294 — Replay attack target with $30 RTL-SDR
RF

Hardcoded ISM-band frequency

Low
CWE-547 — 433/315/868/915 MHz — band as load-bearing
RF

LoRa / sub-GHz without encryption

High
CWE-319 — Payloads world-readable for kilometres
NFC

MIFARE Classic in use

High
CWE-327 — Crypto1 broken since 2008 — clone in seconds
NFC

Authorisation by tag UID only

High
CWE-290 — UIDs are world-readable + emulable
IoT

MQTT over plain TCP (no TLS)

High
CWE-319 — Topics + creds in clear on port 1883
IoT

CoAP without DTLS

Medium
CWE-319 — Unauthenticated UDP — tampering trivial
Code Title Surface Default Severity Status

WIFI.01

WEP and WPA/TKIP must not be used
Wi-Fi
Critical
Passed

WIFI.02

WPA3-SAE or WPA3-Enterprise required
Wi-Fi
High
Passed

WIFI.03

WPS must be disabled on all access points
Wi-Fi
High
Passed

WIFI.04

SSIDs and PSKs must not be hardcoded
Wi-Fi
Critical
Violated

WIFI.05

Open / unauthenticated SSIDs prohibited
Wi-Fi
High
Passed

WIFI.06

Enterprise SSIDs must use 802.1X
Wi-Fi
Medium
Partial

WIFI.07

WIDS/WIPS coverage in regulated env
Wi-Fi
Medium
Partial

BT.01

Default / weak pairing PINs prohibited
Bluetooth
Critical
Passed

BT.02

Secure Simple Pairing with MITM required
Bluetooth
High
Violated

BT.03

BLE LE Secure Connections must be enabled
BLE
High
Violated

BT.04

Just Works prohibited on sensitive chars
BLE
High
Violated

BT.05

GATT must require encryption + auth
BLE
Medium
Partial

BT.06

Per-device passkey / bonding key
BLE
Critical
Passed

BT.07

Discoverable mode limited to short window
Bluetooth
Medium
Passed

BT.08

Bluetooth 5.2+ Secure Connections Only
Bluetooth
Medium
Passed

RF.01

Rolling-code or AES-CTR (no fixed-code)
RF
High
Passed

RF.02

RF payloads cryptographically authenticated
RF
High
Passed

RF.03

LoRa / sub-GHz with LoRaWAN OTAA + AES
RF
High
Passed

NFC.01

Migrate from MIFARE Classic to DESFire EV2/EV3
NFC
High
Violated

NFC.02

No authorisation by tag UID alone
NFC
High
Passed

IOT.01

Default Zigbee TC link key prohibited
IoT
Critical
Passed

IOT.02

MQTT must run over TLS (port 8883)
IoT
High
Violated

IOT.03

CoAP must run over DTLS 1.2+
IoT
Medium
Partial

IOT.04

Per-device unique creds at manufacturing
IoT
High
Passed

Findings by surface

Severity distribution

🛡️ Security AI