Back

MEDIUM

Tropos Wireless Mesh Routers Insufficient Entropy

Published Dec 18, 2012

Description

Mesh OS before 7.9.1.1 on Tropos wireless mesh routers does not use a sufficient source of entropy for SSH keys, which makes it easier for man-in-the-middle attackers to spoof a device or modify a client-server data stream by leveraging knowledge of a key from a product installation elsewhere.

Affected products

Remediation

Vendor solution

Tropos Networks has released customer notification and an update (Tropos Mesh OS 7.9.1.1) for its network device embedded software. This update can be downloaded from the Tropos software download page. Download of the update requires a valid user name and password. The updated firmware fixes the vulnerability by using sufficient entropy to generate unique SSH host keys.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner icscert
Published Dec 18, 2012
Updated Jul 9, 2025
Reserved Sep 12, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a