We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

Kr00k Wi-Fi® Vulnerability

Overview


Kr00k is a Wi‑Fi vulnerability that affects certain Wi-Fi Protected Access II (WPA2) implementations during the device disassociation process. Under specific conditions, an attacker within wireless range may trigger a disconnection event that causes impacted devices to transmit limited data using an all-zero encryption key during the disassociation process.

The issue is related to how encryption keys are cleared when a device disconnects from an access point. Kr00k impacts data confidentiality during a narrow operational window and does not enable arbitrary code execution or persistent device compromise. Exploitation requires proximity and occurs only during a limited disassociation window.

We have evaluated our Wi-Fi products for this vulnerability, and no action is required. 

Vulnerabilities Covered


This page addresses the following Kr00k‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs):

  • CVE-2019-15126: Encryption with an all-zero session key (TK) after disassociation

Affected Products and Resolution


Last Updated: June 30, 2026

Our Wi‑Fi devices are not known to be impacted by the Kr00k vulnerability.

Reference Documentation


Reference documentation includes the following third-party research material:

Live Chat

Need Help?

Privacy Policy