Cisco is working on a set of patches to address a newly disclosed vulnerability that can be exploited to intercept Wi-Fi network traffic. The vulnerability, reported as CVE-2019-15126, is called “Kr00k” and was disclosed at the RSA 2020 security conference in San Francisco by researchers from ESET on Wednesday.
Kr00k is a vulnerability that allows hackers to force Wi-Fi systems into catastrophic states by affecting the decryption capability used to secure data packets.
All Wi-Fi devices powered by Broadcom or Cypress Wi-Fi chips are affected. ESET has said the number affected is around one billion, which it calls a “conservative estimate.”.
Patches are being applied by vendors using these chips, and it is also possible to mitigate attacks using the newer WPA3 protocol.
Cisco is currently investigating how widespread the Kr00k vulnerability is within its products, as a user of a Broadcom chip.
The giant company said Thursday that "Cisco is investigating product to determine which products may be affected by this vulnerability," but preliminary investigations have shown that "multiple" devices are affected.
According to Cisco, the Kr00k vulnerability affects a range of Power over Ethernet (PoE) routers, firewall products, IP phones and endpoint systems , as you can see below:
Cisco is currently investigating the vulnerability of Cisco DX70, DX80, and DX650 IP Phones running Android firmware, as well as the Cisco IP Phone 8861.
The company has not yet developed the patches to resolve the security flaw but it seems we can expect them soon.

