Keyspace List for WPA on Default Routers
I've been working on the 5268's, not gonna clog up this thread with what I've found but if anyone's interested in collaborating please send me a PM.
Been comparing 5286AC-FXN credentials.

There is a clear correlation between the first six digits of the MAC, and the first five digits of the S/N.

I'll list the pictures I used to deduce this.

MAC F8:18:97:1EBig GrinD:1C , S/N 18151N018859

MAC F8:18:97:08:A8:64 , S/N 19151N004762

Same thing with these two


And these three




You can definitely see a pattern in the S/Ns.

The last six digits of the S/N are probably a unique ID. not sure if any of this will yield anything, but it is interesting so I thought I'd share.
(10-16-2020, 09:45 AM)Red1337 Wrote: [ -> ]Been comparing 5286AC-FXN credentials.

There is a clear correlation between the first six digits of the MAC, and the first five digits of the S/N.

The 2Wire/Pace serial number has the form 'aabbcdeeeeee'. 
Here 'aa' is 2 digits possibly encoding the manufacture date (observed possible first digits include 1,2,3,4, and 9.) 
'bb' is the year ('12' for 2012, etc.), 'c' is almost always 1. 'd' varies, its exact meaning is unclear,but all observed 3801's have a '9' here, all observed 5268AC's have a 'N', and other devices vary.

Source: http://en.techinfodepot.shoutwiki.com/wi...26T_Uverse

For the 589 and 599, (and probably the bgw210s?) the serial is just the mac-1 converted to decimal
I built a different version of genpass5268... I'm getting the echos but much more consistent, hence I get keys that are a few points off from yours but they ALL result in the correct answer for example pwd=2aek7%tyw+nt
All these keys give the correct password (it doesn't skip like yours)


Which brings me to the multiplier/divisor/seed. I think I can brute force it, but it'll take years to get to 5 decimal places. With the 589 we can spot the minimum at a 0.1 resolution and can refine it after that to get more decimal places. What is the clever way to do it?
I am trying to identify Huawei and Arris default key spaces. Does anyone have that info?
or simply take a look at hcxpsktool:
It covers several algos (based on analysis of wpa-sec submissions).
Most of them are not covered by RouterKeyGen, because hcxpsktool calculate the entire key space, instead of a single hit.
This behavior is wanted due to analysis purpose, especially in combination with hcxdumptool attacks on CLIENTs (we don't have the origin MAC AP on this attack vector).
Alrighty.... Let's get back to this 5268ac thingy. I've been collecting more passwords and some interesting statistics show up (see pictures) 
After one letter (going right to left) the odds of getting another letter are about half of getting a number or symbol. 
After 2 letters, the odds of getting another letter are about a third of getting a number or symbol. 

After three letters you'll definitely get a number or a symbol (unless the sequence starts with the very last letter, then you can have 4 letters in a row) 
After a symbol it is also forbidden to get another symbol (letter or number only) So a lot of weird statistics going on!

Most of this has been described up thread, so nothing really new, but I'm practically starting over with the analysis.
Based on Farts comments, I'm probably chasing my tail (red herring) and all this falls out automatically when I finally get the correct multiplier. But haven't had any luck with that yet. But I finally have more time, so may be I can get it this summer.

This kinda belongs in this thread...
CGM4140COM routers have a default password that doesn't quite fit in the hybrid mode or the combinator mode

wordlist ?d?d?d?d wordlist

Any suggestions how to tackle this one? Do we need an -a 8?
