The flaw in the Wi-Fi Protected Access (WPA) standard was highlighted in a research paper published on 4 November by Trusecure senior technical director Robert Moscovitch.
The flaw allows intruders to crack passphrases of less than 20 characters via an offline dictionary attack - where a hacker takes the password file from the server then cracks it with dictionary software.
Stan Schatt, an analyst with Giga, said, "The problem is that suppliers do not provide an easy-to-use tool with which to generate and manage 20-character passphrases."
Schatt said it was impractical for companies to rely on WPA for security and that they must use authentication servers for 802.1x security.
WPA was unveiled in late-2002 as a replacement for WEP (Wired Equivalent Privacy), the existing, but flawed, basic wireless security method.
Where WEP uses a predictable static key, WPA uses integrity checking protocols for its encryption. If, however, users employ short text-based keys, these can be cracked and it is recommended that complex keys with random characters are used to foil dictionary analysis.