WPS Attack
What is WPS Attack?
WPS AttackAn online brute-force attack on the eight-digit Wi-Fi Protected Setup PIN that recovers the WPA/WPA2 passphrase in hours.
Wi-Fi Protected Setup (WPS) was designed to simplify joining a home network using an eight-digit PIN. In December 2011 Stefan Viehböck — and independently Craig Heffner — disclosed a fatal design flaw, documented in US-CERT VU#723755 and tracked as CVE-2011-5053. When the external-registrar method authenticates the PIN, the access point validates it in two halves and returns an EAP-NACK that reveals whether the first half was correct before the second is checked. Because the eighth digit is only a checksum of the first seven, the search space collapses from 10^8 (100 million) to 10^4 + 10^3 ≈ 11,000 attempts.
Tools such as Reaver (Craig Heffner / Tactical Network Solutions) and Bully (Sofiane Talmat) exploit this against most consumer access points and recover the WPA/WPA2 pre-shared key in roughly 4–10 hours. The related Pixie Dust attack (Dominique Bongard, 2014) goes further, breaking WPS offline in seconds on routers with weak nonce randomness in the registration exchange.
Defence: disable WPS entirely, or restrict it to push-button (PBC) mode; vendors also added PIN-attempt rate limiting and lockouts after repeated failures. Many cheap routers still ship with the vulnerable external-registrar PIN method enabled by default.
flowchart TD
A[Attacker in radio range] --> B[Send WPS PIN guess to access point]
B --> C{First 4 digits correct?}
C -->|EAP-NACK early| D[Wrong first half: try next of 10^4]
C -->|Proceeds| E{Last 3 digits plus checksum correct?}
E -->|EAP-NACK| F[Wrong second half: try next of 10^3]
E -->|Success| G[AP returns WPA/WPA2 pre-shared key]
D --> B
F --> B
G --> H[Attacker joins the network]● Examples
- 01
Running Reaver against an older home router to recover the WPA2 passphrase in a few hours.
- 02
Bully iterating the lower half of the WPS PIN once the upper half has been confirmed.
● Frequently asked questions
What is WPS Attack?
An online brute-force attack on the eight-digit Wi-Fi Protected Setup PIN that recovers the WPA/WPA2 passphrase in hours. It belongs to the Attacks & Threats category of cybersecurity.
What does WPS Attack mean?
An online brute-force attack on the eight-digit Wi-Fi Protected Setup PIN that recovers the WPA/WPA2 passphrase in hours.
How do you defend against WPS Attack?
Defences for WPS Attack typically combine technical controls and operational practices, as detailed in the full definition above.
What are other names for WPS Attack?
Common alternative names include: WPS PIN brute-force, Reaver attack.