Kr00k is a Wi‑Fi vulnerability that affects certain Wi-Fi Protected Access II (WPA2) implementations during the device disassociation process. Under specific conditions, an attacker within wireless range may trigger a disconnection event that causes impacted devices to transmit limited data using an all-zero encryption key during the disassociation process.
The issue is related to how encryption keys are cleared when a device disconnects from an access point. Kr00k impacts data confidentiality during a narrow operational window and does not enable arbitrary code execution or persistent device compromise. Exploitation requires proximity and occurs only during a limited disassociation window.
We have evaluated our Wi-Fi products for this vulnerability, and no action is required.
This page addresses the following Kr00k‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs):
CVE-2019-15126: Encryption with an all-zero session key (TK) after disassociation
Last Updated: June 30, 2026
Our Wi‑Fi devices are not known to be impacted by the Kr00k vulnerability.
Reference documentation includes the following third-party research material:
Vulnerability whitepaper: Kr00k CVE-2019-15126
Live Chat