Router, modem error icon
– Getty Images

Networking devices are still vulnerable to a Wi-Fi attack method unearthed more than a decade ago, according to a report from NetRise.

First teased in 2011, before being formalized in 2014, the "Pixie Dust" exploit takes advantage of weaknesses in the Wi-Fi Protected Setup (WPS) protocol's cryptographic implementation. Instead of brute forcing WPS pins, Pixie Dust leverages poor random number generation to quickly recover the eight-digit WPS pin, revealing the network password regardless of its strength.

Despite being known for more than a decade, NetRise suggests that networking equipment being used today is still vulnerable to Pixie Dust. The firm analyzed firmware from 24 devices across six vendors, including routers, access points, and range extenders.

Its findings were stark: Of the 24 devices, only four were ever patched, with the earliest released some nine years following the exploit coming to light.

According to NetRise, some 13 of the 24 devices remain actively supported but unpatched, while another seven reached their end of life without ever receiving fixes.

"Pixie Dust is more than a vulnerability. It's a case study in how insecure defaults and weak patching processes persist in firmware," NetRise CEO Thomas Pace explained. “Relying on vendor self-attestation isn't good enough for enterprises that deploy devices such as these. Creating a comprehensive and accurate software bill of materials (SBOM) by analyzing the compiled code that's on the device is the only way to uncover and manage risk.”

The persistence of Pixie Dust vulnerabilities shows broader systemic issues within the networking equipment industry. NetRise's analysis of Wi-Fi devices revealed that vulnerable firmware was even released as recently as 2025 – more than a decade after the exploit's initial disclosure. On average, vulnerable releases occurred 7.7 years after Pixie Dust was first published, with the oldest vulnerable firmware in the study dating back to September 2017.

Most concerning is how the attack actually works in practice. An attacker needs only to capture a single wireless exchange while within range of the target network. The actual brute forcing of the WPS PIN can then occur offline and can be completed in mere seconds using widely available automated tools.

While many devices released in the years that followed Pixie Dust’s emergence may seem secure due to UI settings that hide or disable WPS superficially, NetRise's research suggests this creates “silent exploit paths.”

“Enterprises cannot reliably detect this exposure, leaving them dependent on vendor disclosures that often never come,” the report reads.