VYPR
Unrated severityNVD Advisory· Published Jun 25, 2021· Updated Sep 16, 2024

WEIDMUELLER: WLAN devices affected by Hard-coded Credentials vulnerability

CVE-2021-33529

Description

In Weidmueller Industrial WLAN devices in multiple versions the usage of hard-coded cryptographic keys within the service agent binary allows for the decryption of captured traffic across the network from or to the device.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hard-coded cryptographic keys in Weidmueller Industrial WLAN devices allow network attackers to decrypt captured traffic.

Vulnerability

In Weidmueller Industrial WLAN devices across multiple versions, the service agent binary contains hard-coded cryptographic keys [1]. This allows an attacker to decrypt traffic captured from or to the device without any special configuration requirements.

Exploitation

An attacker with network access to the device's communication can capture encrypted network traffic. Using the hard-coded keys extracted from the binary, the attacker can decrypt the captured traffic to obtain plaintext data [1]. No authentication or user interaction is required.

Impact

Successful exploitation results in complete loss of confidentiality for all network traffic between the device and other hosts. The attacker can read sensitive information such as credentials, control commands, or industrial process data [1].

Mitigation

No mitigation details are provided in the available reference [1]. Users should contact Weidmueller for updated firmware or consider network segmentation to limit exposure until a fix is available.

References
  1. Advisories

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Weidmüller/IE-WL(T)-BL-AP-CL-XXv5
    Range: IE-WL-BL-AP-CL-EU (2536600000)
  • Weidmüller/IE-WL(T)-VL-AP-CL-XXv5
    Range: IE-WL-VL-AP-BR-CL-EU (2536680000)

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.