Case Study: Wireless Network Security Testing
Wireless networks extend the enterprise attack surface beyond walls, switches and managed endpoints. Weak credential handling, open access, insecure management protocols and unaccounted-for access points can provide an unauthorised route towards internal infrastructure even where the principal corporate wireless service is well configured.
This case study outlines an onsite ProCheckUp wireless security assessment of a multi-floor environment supporting corporate users, guests, device-management services and operational equipment. The engagement combined radio-frequency discovery, controlled association testing, configuration analysis, segmentation checks and physical correlation of access points.

Overview
A large UK organisation commissioned ProCheckUp to assess the security of its wireless estate and determine whether an unauthorised person within radio range could gain access, intercept traffic, reach management services or exploit devices outside the approved access-point inventory.
The assessment considered separate wireless roles rather than treating Wi-Fi as one homogeneous environment. Corporate access used enterprise authentication, while guest, device-management and operational networks applied different encryption and credential models. The review also examined the management plane, RADIUS and SNMP configuration, wireless-to-wired boundaries and the relationship between detected radio signals and centrally managed infrastructure.
The engagement identified eight findings: four High, two Medium, one Low and one Informational. The most direct risks were publicly visible Wi-Fi credentials that enabled a successful test connection, an internal management interface accessible over HTTP, mixed wireless-security standards, and a weak local administrative password policy.
Engagement at a glance
- - Multi-floor onsite wireless survey across applicable channels and hidden SSIDs
- - Corporate, guest, device-management and operational wireless roles considered
- - Unauthorised-client, authenticated-user and configuration-review perspectives
- - NetAlly AirCheck G3E Pro, used for RF discovery and survey activity
- - Controlled association, management-access and segmentation validation
- - Potential rogue and unmanaged access points identified for ownership investigation
Challenge
Wireless assurance requires radio-frequency evidence, logical testing and physical context. A strong signal does not, by itself, prove that an access point is malicious or even located inside the customer’s premises. Equally, an access point connected to the customer’s Ethernet network cannot be dismissed as harmless neighbouring radio noise.
Shared radio space
The site received signals from centrally managed access points, neighbouring organisations, consumer broadband equipment and devices outside the approved wireless inventory. Each observation needed to be classified through signal strength, BSSID and vendor information, controller inventory, floor-by-floor coverage and physical inspection.
Mixed trust and authentication models
Corporate 802.1X access, open guest connectivity and pre-shared-key operational networks coexisted in the same physical RF environment. These services created materially different assumptions around identity, encryption, credential distribution and accountability.
Live-environment constraints
Testing had to remain non-disruptive. Connectivity and validation were completed for the guest and operational networks, but full corporate-network segmentation testing was constrained because the required credentials were not supplied. Direct access to access-point and controller configuration was also unavailable, so parts of the review relied on configuration screenshots and observed behaviour.
Assessment Scope
The public case study generalises the original network names into functional roles. Testing concentrated on the following areas:
- - Corporate wireless: enterprise authentication, encryption strength, 802.1X behaviour, protected management frames and client-access assumptions
- - Guest wireless: unauthenticated association, link-layer encryption, captive-portal expectations, isolation and traffic-control exposure
- - Device-management wireless: pre-shared-key handling, brute-force resistance and suitability for individual enterprise authentication
- - Operational-device wireless: shared-key risk, availability considerations and segmentation from sensitive resources
- - Management plane: HTTP and HTTPS use, administrative password policy, logging, RADIUS and SNMP security
- - RF and access-point inventory: visible and hidden SSIDs, applicable channels, signal mapping, central-management correlation and physical investigation
Solution
ProCheckUp combined purpose-built wireless survey equipment, controlled testing and manual evidence correlation. A NetAlly AirCheck G3E Pro was used to support onsite discovery of wireless networks, channels, signal strength, security modes and access-point identities across the assessed floors.
The assessment followed four stages:
- 1. Discover: enumerate applicable channels, visible and hidden SSIDs, BSSIDs, vendors, security modes, signal levels and coverage.
- 2. Associate: safely test authorised connection paths, including the practical effect of exposed credentials and the behaviour of open or pre-shared-key networks.
- 3. Validate: assess encryption, 802.1X, protected management frames, RADIUS, SNMP, management protocols, password policy and wireless-to-wired segmentation within the agreed limits.
- 4. Correlate: compare RF observations with the central controller inventory, heatmaps, wired-network evidence and physical inspection to identify devices requiring ownership investigation.
Manual validation remained decisive. The assessment distinguished a neighbouring signal from an unknown device, an unknown device from an Ethernet-connected access point, and a potential rogue access point from a device proven to be malicious. Findings were rated using CVSS v3.1 as recorded in the source assessment.

Vulnerabilities Identified
The eight findings connected wireless configuration and operational practice to practical access risk.
Public visibility of Wi-Fi credentials — High, CVSS 7.5
Wireless credentials were displayed in an area accessible to unauthorised people. A ProCheckUp consultant used the exposed credentials to connect successfully, converting a procedural weakness into a validated unauthorised access path.
Recommendation: remove all public copies, rotate the affected credential, use a controlled identity-aware distribution process and monitor association logs for unexpected clients.
Management interface accessible over HTTP — High, CVSS 8.8
An internal network-management interface was reachable over unencrypted HTTP. A local attacker with network access could potentially observe administrator credentials or session data in transit.
Recommendation: disable HTTP, enforce HTTPS with a valid certificate, restrict management access to approved administrative networks, enable MFA and review access logs.
Wireless-security standards required improvement — High, CVSS 7.6
The corporate service used WPA2-Enterprise, AES-CCMP and 802.1X, providing a sound baseline. The wider estate, however, included an open guest network, WPA2-PSK operational networks and protected management frames that were not required.
Recommendation: migrate suitable networks towards WPA3-Enterprise, replace shared keys with individual 802.1X authentication and require protected management frames where client compatibility permits.
Weak wireless-management password policy — High, CVSS 7.3
Local management policy allowed very short passwords, imposed no meaningful character requirements, did not require expiry and did not enforce account lockout. This materially reduced resistance to password guessing and brute-force attempts.
Recommendation: require long passwords or passphrases, block weak and common values, enable failed-login lockout and MFA, remove unused local accounts and centralise privileged access where possible.
RADIUS security enhancements required — Medium, CVSS 6.1
Controller-to-RADIUS communications were not consistently protected. IPsec was disabled, AES Key Wrap was applied inconsistently and several supporting settings required validation.
Recommendation: encrypt controller-to-RADIUS communications, apply key-protection controls consistently, remove unused servers and repeat segmentation validation.
Unencrypted guest wireless network — Medium, CVSS 5.3
The guest service allowed association without link-layer encryption, exposing local user traffic to interception and providing limited accountability for network use.
Recommendation: use WPA2 or WPA3 encryption with a secure captive portal, maintain strict isolation from corporate and management services, and apply monitoring, ACLs and proportionate traffic controls.
SNMP configuration weaknesses — Low, CVSS 3.8
SNMPv2c remained enabled and SNMPv3 was not enforced as the sole management protocol. Weak authentication and privacy choices reduced protection for monitoring traffic and credentials.
Recommendation: disable SNMPv2c, require SNMPv3 with strong authentication and AES privacy, restrict authorised management sources and review monitoring credentials.
Unknown and potential rogue access points — Informational, CVSS 0.0
Strong unknown SSIDs were detected within the building. Some appeared consistent with neighbouring or consumer equipment; others were outside the centrally managed wireless estate and appeared to be physically connected to Ethernet.
Recommendation: physically locate each relevant device, establish ownership and installation purpose, compare it with an authoritative access-point inventory, correlate it to switch ports and segmentation, and enable continuous rogue-device detection and alerting.
Potential Rogue Access Points
The assessment’s multi-floor heatmaps, full-channel discovery and onsite inspection identified access points that were not present in the central wireless-management inventory. The evidence required three distinct classifications:
- - Neighbouring signal: visible within radio range but not necessarily located on, or connected to, the customer’s network
- - Unknown or unmanaged access point: not reconciled with the approved inventory and therefore requiring ownership and configuration checks
- - Ethernet-connected access point: outside central management but associated with the wired environment, making physical and switch-port investigation a priority
Important evidence boundary: potential rogue access points were found, but the assessment did not establish that a specific unknown device was installed or controlled by a malicious actor. The defensible response is rapid ownership validation, physical inspection and containment where authorisation cannot be demonstrated.
Recommended governance measures include enabling rogue-access-point detection and alerting on the central wireless platform, maintaining an accurate AP and BSSID inventory with physical locations, monitoring for impersonated or unexpected SSIDs, and repeating periodic RF surveys and wired-port reconciliation.
Authorised Risk Model
The following sequence explains how the confirmed findings could combine into a broader management-plane risk:
- 1. Credential exposure — confirmed: a wireless password was visible to unauthorised people.
- 2. Network association — confirmed: the exposed credential successfully connected a test device.
- 3. Management discovery — observed: an internal network-management interface was reachable from the connected context.
- 4. Traffic interception — potential: HTTP could expose administrator credentials or session information to a local attacker.
- 5. Control-plane access — potential: intercepted credentials could enable unauthorised infrastructure administration.
- 6. Broader impact — potential: infrastructure control could support disruption, reconnaissance or lateral movement.
This is an authorised risk model, not evidence of a completed real-world compromise. The early stages were validated during testing; the later stages describe the credible consequence of the observed controls and were not claimed as executed.
Control Effectiveness and Assessment Boundaries
Positive controls observed
- - The corporate wireless service used WPA2-Enterprise, 802.1X and AES-CCMP
- - Multiple RADIUS servers provided authentication and accounting resilience
- - Segmentation between certain shared wireless services reduced straightforward lateral movement
- - Multi-floor RF evidence allowed unknown signals to be considered in physical context
Limitations requiring follow-up
- - Full corporate-network segmentation validation could not be completed without the required credentials
- - Direct access to controller or access-point configuration was unavailable; screenshots supported parts of the review
- - Unknown access points required ownership confirmation before final classification
- - The source material did not confirm that recommended changes were later implemented or independently retested
The assessment proved that the exposed credential was usable, the management interface accepted HTTP, an in-scope guest service operated without link-layer encryption and unmanaged access points existed. It did not prove that an unknown AP was malicious, that administrator credentials were intercepted or that controller compromise and lateral movement occurred.
Outcome
The engagement converted an uncertain radio-frequency landscape into a prioritised wireless-security programme. The customer received evidence showing not only which settings were weak, but how credential handling, management exposure, mixed authentication models and unmanaged equipment combined to create credible access paths.
Infrastructure, security and facilities teams were given a common triage order. Direct access paths — publicly visible credentials, HTTP management and unexplained access points — could be addressed before broader architecture improvements such as WPA3 migration, protected management frames and management-protocol modernisation.
The assessment also preserved important distinctions: strong corporate controls were recognised, unknown signals were not automatically declared malicious, and testing limitations were documented rather than replaced with assumptions.
Immediate containment
- - Remove publicly displayed credentials and rotate affected wireless secrets
- - Disable HTTP and enforce HTTPS on every management interface
- - Locate, validate and isolate unauthorised or unexplained access points
- - Restrict management traffic and review unexpected client associations
Engineering hardening
- - Migrate appropriate networks towards WPA3-Enterprise
- - Replace shared PSKs with individual 802.1X authentication
- - Require protected management frames
- - Strengthen privileged passwords, lockout and MFA
- - Secure RADIUS transport and standardise key protection
- - Retire SNMPv2c and enforce strongly configured SNMPv3
- - Retest segmentation between corporate, guest and operational networks
Sustained wireless governance
- - Maintain an authoritative access-point, BSSID and physical-location inventory
- - Alert on new SSIDs, impersonated network names and unknown wired access points
- - Repeat multi-floor RF surveys after significant infrastructure changes
- - Periodically verify coverage, roaming, authentication and segmentation controls
- - Coordinate network, security and facilities ownership of wireless equipment
The Core Security Lesson
Wireless security is an ownership and trust-boundary problem, not only an encryption setting.
Strong assurance requires secure credential distribution, protected management, individual authentication, reliable segmentation, complete RF visibility and confidence that every access point connected to the network is authorised, configured and monitored.
The correct question is not simply:
“Which encryption standard does this SSID use?”
It is:
“Which devices, credentials and wired paths actually define our wireless perimeter?”
How ProCheckUp Helps
ProCheckUp’s Wireless Network Security Testing service assesses the complete relationship between radio exposure, authentication, management infrastructure and the wired network. Support can include:
- - Multi-floor RF surveying and heatmap analysis
- - Visible and hidden SSID, channel, BSSID and vendor discovery
- - Rogue and unauthorised access-point investigation
- - WPA2, WPA3, 802.1X, EAP and pre-shared-key assessment
- - Protected management frame and deauthentication-resilience review
- - Guest, corporate and operational network segmentation testing
- - RADIUS, SNMP and wireless-controller configuration review
- - Credential-distribution and privileged-access assessment
- - Wireless-to-wired attack-path validation
- - Prioritised remediation and verification testing
Related services include Wireless Testing, Infrastructure Testing and Penetration Testing.
Conclusion
This engagement demonstrated why wireless assurance must connect what is visible in the air with what is authorised on the network. The decisive risks were not isolated configuration entries: they were the interaction between exposed credentials, insecure management, open or shared-key services and access points that had not been reconciled with central ownership.
By combining credential control, secure management, modern enterprise authentication, segmentation, continuous rogue-device monitoring and repeat RF surveys, organisations can reduce the likelihood that the wireless estate becomes an unmonitored route into sensitive infrastructure.
To discuss a wireless security assessment, rogue-access-point investigation or wider network penetration test, contact ProCheckUp.
For More Information Please Contact Us
ACCREDITATIONS
