CVE-2025-63363

7.5

Waveshare · RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway

A lack of Management Frame Protection in Waveshare RS232/485 TO WIFI ETH (B) gateways allows unauthenticated attackers to perform de-authentication attacks.

Executive summary

The Waveshare RS232/485 TO WIFI ETH (B) gateway is vulnerable to unauthenticated de-authentication attacks due to a lack of Management Frame Protection, posing a significant risk to network availability.

Vulnerability

The device fails to implement Management Frame Protection, allowing an unauthenticated attacker to broadcast crafted de-authentication and disassociation frames, which forces connected clients to disconnect from the wireless network.

Business impact

Successful exploitation results in a denial of service for wireless clients connected to the gateway. Given the CVSS score of 7.5, this high-severity vulnerability could lead to significant operational disruption in industrial or commercial environments where reliable serial-to-ethernet communication is critical for business processes.

Remediation

Immediate Action: Since a specific patch is not yet identified, restrict access to the wireless management interface and monitor vendor communications for firmware updates.

Proactive Monitoring: Monitor network logs for a high volume of de-authentication frames or unexpected client disconnections, which may indicate an active attack.

Compensating Controls: Implement physical security and signal shielding to limit access to the radio frequency environment, and ensure that sensitive traffic is encrypted at the application layer to prevent further impact if connectivity is disrupted.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a high risk to operational continuity due to the potential for unauthenticated denial of service. Organizations utilizing these gateways should prioritize limiting exposure to the wireless environment and maintain vigilance for firmware updates from Waveshare to address the lack of management frame protection.

Sources