Researchers have uncovered a new vulnerability, resulting from a flaw in the design of IEEE 802.11 Wi-Fi.

This vulnerability tricks victims into connecting to a more secure wireless network, allowing their online movements to be monitored.
The “SSID Confusion” attack, tracked as CVE-2023-52424, affects all operating systems and Wi‑Fi devices, regardless of whether they are home or enterprise networks, including protocols such as WEP, WPA3, 802.11X/EAP, and AMPE.
See also: Hackers target Foxit PDF Reader users and distribute malware
The method involves relegating victims to a less secure networkby spoofing a trusted network name (SSID), thus allowing their online movements to be monitored or further attacks to be carried out, according to Top10VPN, which collaborated with KU Leuven professor and researcher Mathy Vanhoef.
“A successful SSID attack leads to the automatic disabling of any VPN using trusted networks, leaving the victim’s internet traffic unprotected.”
The attack is based on the fact that Wi-Fi does not necessarily enforce verification of the network name's identity (SSID or Service Set Identifier), leaving security measures to be activated only when a device decides to connect to a specific network.
The direct result of this combination of behaviors is that a hacker has the ability to trick a user into connecting to an unsecured Wi-Fi network, instead of the originally desired network, thus conducting a “Man in The Middle” (MitM) attack.
«In our attacks, when the victim tries to connect to the TrustedNet network, we deceive them to connect instead of that to one of our own networks, the WrongNet, using similar credentials», explained the researchers Héloïse Gollier and Vanhoef. “Thus, the victim is informed that they have connected to TrustedNet, while in reality they are connected to WrongNet.”
In other words, even when credentials such as passwords are verified during the login process to a protected Wi‑Fi network, there is no absolute certainty that the user is actually connected to the desired network.
Read more: Android adds anti-theft data protection
To remove the attack, there are specific steps.
- The victim attempts to connect to a safe and reliable Wi‑Fi network
- A reliable network is available, using the same authentication certificates as the original.
- The hacker is within the required distance to carry out a “Man in the Middle” attack between the victim and the trusted network.
To address SSID confusion issues, it is proposed to update the Wi-Fi 802.11 standard to incorporate the SSID into the 4-way handshake process when connecting to secure networks. Additionally, improvements to protection , which allows a user to store a reference beacon containing the network SSID, will enhance network authentication during the 4-way handshake.
Beacons signals periodically emitted by wireless access points, as part of a management system, to signal their presence. They contain critical information such as the SSID, the beacon's broadcast frequency, and available network features.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Researchers state that networks can prevent attacks by avoiding the reuse of credentials across different SSIDs. Specifically, corporate networks should implement distinct Common Names for RADIUS servers, while home networks should use a unique password for each SSID.

See also: How to find a Wi-Fi password on a Mac
The discoveries come nearly three months after two major vulnerabilities were revealed in open-source Wi-Fi software, such as wpa_supplicant and Intel's iNet Wireless Daemon (IWD). These flaws allow users to be tricked into connecting to malicious networks that mimic legitimate connections or allow hackers to register on trusted networks without requiring a password.
Last August, Vanhoef revealed that the Windows for Cloudflare WARP could be tricked into revealing all DNS requests, thereby allowing a hacker to spoof DNS responses and redirect almost all web traffic.
Source: thehackernews
