Skip to content
Cyber Defense Technologies

Threat Intelligence

Wireless and RF Attack Surfaces Organizations Overlook

Radio signals do not stop at the fence line. The wireless attack surfaces organizations often miss, including Wi-Fi, Bluetooth, cellular, satellite and industrial radio, and how to assess and reduce them.

By Cyber Defense Technologies August 11, 2026 4 min read

Most network security assumes an attacker must either break in from the internet or get physically inside. Wireless technologies break that assumption. A signal that leaks beyond a building's walls can be reached from a parking lot, a neighboring building, a vehicle or even a drone.

Many organizations secure their corporate Wi-Fi reasonably well and then forget about everything else that transmits.

Wireless attack surfaces

  1. Wi-Fi

    Rogue and evil twin access points, weak authentication, guest networks that reach internal systems.

  2. Bluetooth and short-range

    Devices discoverable and vulnerable to nearby attackers.

  3. Cellular

    Fake base stations and downgrade attacks, and devices with built-in cellular modems.

  4. Satellite

    Terminals and links with management interfaces and weak configuration.

  5. Other RF

    Radios, telemetry, industrial wireless and building systems.

Wi-Fi

Wi-Fi remains the most familiar wireless attack surface, and common weaknesses persist:

  • Rogue access points plugged into the network by employees or attackers, bypassing security controls
  • Evil twin access points that impersonate legitimate networks to capture credentials or intercept traffic
  • Weak authentication, such as shared passwords on networks that reach sensitive systems
  • Misconfigured enterprise authentication where devices do not validate the authentication server's certificate, allowing credential capture
  • Guest networks that are not properly isolated from internal systems

Bluetooth and short-range wireless

Laptops, phones, headsets, keyboards, medical devices and industrial equipment use Bluetooth and other short-range protocols. Vulnerabilities in these protocols and devices have been discovered repeatedly, and discoverable or poorly secured devices can be targeted by nearby attackers.

Cellular

  • Devices with built-in cellular modems, such as routers, IoT gateways, vending machines, vehicles and industrial equipment, can create network paths that bypass the corporate perimeter entirely. They are often missing from asset inventories.
  • Fake base stations, sometimes called IMSI catchers or cell-site simulators, can impersonate legitimate cell towers to track devices or attempt to intercept communications. U.S. government officials have acknowledged detecting such devices in the Washington, D.C., area.
  • Downgrade attacks can force devices onto older, weaker network generations.

Satellite

Satellite terminals support remote sites, maritime and aviation operations, and backup communications. Terminals may have management interfaces, default credentials or outdated firmware, and in armed conflicts satellite communications infrastructure has been deliberately targeted. They deserve the same scrutiny as any other network edge device.

Industrial and other RF

Facilities use radio for building systems, telemetry, sensors, access control, push-to-talk radios and industrial control. Some of these protocols lack authentication or encryption, and some can be replayed or jammed.

Assessing your wireless exposure

A wireless assessment should:

  • Survey the spectrum in and around facilities to identify every transmitting device and network, authorized or not
  • Map signal leakage to see where signals can be received outside the perimeter
  • Test Wi-Fi security, including authentication, certificate validation, segmentation and guest isolation
  • Look for rogue and impersonating access points
  • Inventory cellular and satellite connectivity in devices and systems
  • Evaluate Bluetooth and other short-range devices in sensitive areas
  • Review industrial and building system radios for unauthenticated protocols

Reducing risk

  • Use strong enterprise authentication for Wi-Fi, with certificate validation enforced on devices
  • Treat wireless networks as untrusted and segment them from sensitive systems
  • Isolate guest networks completely
  • Detect rogue access points with wireless intrusion detection
  • Add cellular-connected devices to asset inventories and control their use
  • Disable unnecessary wireless interfaces, including Bluetooth where it is not needed
  • Include wireless in penetration testing scope
  • Consider signal containment for highly sensitive spaces

Frequently asked questions

Is WPA3 enough? WPA3 improves Wi-Fi security significantly, but configuration, device support, segmentation and rogue access point detection still matter.

How often should wireless be assessed? At least annually, after significant facility or network changes, and more frequently for sensitive facilities.

Can we legally detect fake cell towers? Detection tools exist, but some techniques involve capturing radio signals, which may raise legal considerations. Seek legal advice before deploying specialized detection.

What to do this week

  • Walk your facilities with a wireless scanner and list every network you can see, including ones you do not recognize.
  • Confirm guest Wi-Fi cannot reach internal systems.
  • Check that devices validate the authentication server's certificate on enterprise Wi-Fi.
  • Identify equipment with built-in cellular modems and add it to your asset inventory.
  • Disable Bluetooth on systems in sensitive areas where it is not needed.

How CDT can help

CDT's penetration testing includes wireless penetration testing of Wi-Fi, encryption and access controls, and our secure systems engineering team designs wireless architectures that hold up. CDT is also developing RAVEN-X WAVES, a planned module of the RAVEN-X platform for RF, cellular, Wi-Fi and satellite assessment environments; it is not yet available and its capabilities may change.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.