Regular Visitor
•
3 Messages
XB10 5 GHz WPA3-Transition Fails on 2 NVIDIA Shields; WPA2 Fixes Both
I'm posting this because I've now reproduced this with two separate NVIDIA Shield devices and isolated it fairly narrowly to the XB10's 5 GHz WPA3-Personal-Transition behavior.
The short version:
Both NVIDIA Shields worked normally with this XB10 for roughly the first 10 days after installation.
Then one Shield abruptly lost Wi-Fi while actively being used. It could still SEE the SSID, but attempting to reconnect failed with "Couldn't find KC Network."
Both Shields now reproduce essentially the same behavior.
Most importantly:
XB10 5 GHz + WPA3-Personal-Transition = BOTH Shields fail to associate.
Change ONLY the XB10 5 GHz security mode to WPA2 = BOTH Shields connect immediately.
The Shields themselves work normally on other 5 GHz access points.
I would appreciate someone familiar with the XB10 / OneWifi stack looking at this rather than repeating basic client troubleshooting.
GATEWAY INFORMATION
Gateway: XB10
Vendor: Technicolor
Model: CGM601TCOM
Hardware revision: 3.0
Firmware/software image: CGM601TCOM_8.5p12s6_PROD_sey
eMTA/DOCSIS software: Prod_25.1_PD & SMC-BL: 7.0.0
Boot: SMC=7.0.0, CM=2.8.48alpha0, BOLT=1.71.05
Core version: 1.0
I installed/received this XB10 around September 6, 2026.
Both NVIDIA Shields worked normally for approximately the first 10 days.
INITIAL FAILURE
Around September 16, one Shield was actively being used when its Wi-Fi connection suddenly dropped.
The Shield could still see my SSID in its available-network scan. However, selecting the network and attempting to connect eventually resulted in:
"Couldn't find (my SSID)"
This was therefore not simply a hidden or missing SSID.
I tried:
- Rebooting the Shield
- Rebooting the XB10
- Forgetting and re-adding the network
- Restarting Wi-Fi on the Shield
- Re-entering credentials
- Forcing 2.4 GHz
- Forcing 5 GHz
None of those steps restored reliable 5 GHz connectivity.
SECURITY-MODE TEST
The XB10 was using WPA3-Personal-Transition on 2.4 and 5 GHz.
I changed the network to WPA2 in the Xfinity app.
The Shield connected.
I changed it back to WPA3-Personal-Transition as a test.
The connection failure returned.
I initially thought this was simply a Shield/WPA3 compatibility issue, but subsequent testing showed something more complicated.
APP / LOCAL-GATEWAY STATE MISMATCH
After changing the network back to WPA2, it worked temporarily.
By the following evening, the Shield was again unable to connect.
At that point:
Xfinity app:
WPA2
XB10 local admin interface at 10.0.0.1:
2.4 GHz = WPA3-Personal-Transition
5 GHz = WPA3-Personal-Transition
6 GHz = WPA3-Personal Only
Later, without me intentionally changing the setting back, the Xfinity app itself also showed WPA3-Personal-Transition again.
I cannot determine from the customer side whether:
- the WPA2 setting failed to persist,
- a cloud/WebConfig configuration was reapplied,
- the app was temporarily displaying stale configuration,
- or some other Wi-Fi configuration process caused the change.
I am simply documenting what both interfaces displayed.
CONTROL TESTS
I then tested the Shields against other access points.
1. Samsung phone 5 GHz hotspot
The downstairs Shield connected to my Samsung phone's 5 GHz hotspot and streamed YouTube normally.
This demonstrates that its 5 GHz radio and 5 GHz networking are functioning.
2. Netgear repeater
Both Shields can connect to my existing Netgear repeater.
The repeater uses WPA2.
3. XB10 2.4 GHz
Both Shields can connect to the XB10's 2.4 GHz network.
While using WPA3-Personal-Transition, however, both have occasionally required one or two attempts and may initially report that they cannot find/connect to the network.
The 2.4 GHz issue is much less severe than 5 GHz, but the association behavior has not been completely clean.
4. XB10 5 GHz with a modern phone
My Samsung phone connects to the XB10's 5 GHz network normally.
Therefore the XB10 5 GHz radio itself is not simply dead.
SPLIT-BAND TEST
I then split the XB10 into separate 2.4 GHz, 5 GHz and 6 GHz SSIDs, removing band steering/unified-SSID selection from the test.
Both NVIDIA Shields behaved essentially identically.
Both:
- Connected to XB10 2.4 GHz, sometimes after a retry
- Connected to the Netgear repeater
- Refused to connect to XB10 5 GHz
- Did not see 6 GHz, which is expected because these Shields are not Wi-Fi 6E clients
At the time, the XB10 local interface showed the 5 GHz radio as:
Mode: 802.11 a/n/ac/ax/be
Security: WPA3-Personal-Transition
Channel selection: Automatic
Channel: 157
The XB10 reports that Wi-Fi mode, security mode, channel selection, channel mode and bandwidth are managed automatically.
Channel 157 is not a DFS channel, so this particular reproduction does not appear to be explained simply by the gateway selecting a DFS channel.
DECISIVE A/B TEST
With the bands still split, I changed ONLY the XB10 5 GHz security setting:
FROM: WPA3-Personal-Transition
TO: WPA2
I did not change the Shields.
I did not move them.
I did not change the 5 GHz channel.
I did not replace the gateway.
Both NVIDIA Shields connected to the XB10 5 GHz network IMMEDIATELY.
This was reproducible on two independent Shield devices in different rooms.
That is the strongest reason I believe this is an XB10 5 GHz WPA3-Personal-Transition interoperability/configuration issue rather than simultaneous failures of two NVIDIA Shields.
CURRENT WORKAROUND / CURRENT RADIO STATE
I have now recombined the SSIDs and selected WPA2 for stability.
After logging back into the XB10 local interface, it currently reports:
2.4 GHz: WPA2-PSK (AES)
5 GHz: WPA2-PSK (AES)
6 GHz: WPA3-Personal Only
I understand that 6 GHz / Wi-Fi 6E requires WPA3, so I am NOT reporting the 6 GHz WPA3-Personal-Only setting as a fault.
The relevant change is that 2.4 and 5 GHz are now actually showing WPA2-PSK (AES), and both Shields can use 5 GHz again.
WHY I SUSPECT SOMETHING CHANGED
This does not appear to be a simple case of "the NVIDIA Shield never supported this configuration."
Both Shields initially operated normally with this XB10 for approximately 10 days.
One then lost connectivity during active use and could no longer reassociate.
The second Shield subsequently reproduced essentially the same 5 GHz behavior.
Nothing was intentionally changed on either Shield before the problem began.
I would therefore like to know whether the gateway received any of the following around September 16-17:
- Firmware/software update
- OneWifi update or restart
- WebConfig/cloud configuration push
- Wi-Fi optimization/configuration change
- Security/cipher configuration change
- Other gateway-side provisioning change
RELEVANT PUBLIC INFORMATION
I understand that public RDK/OneWifi development does not necessarily map one-for-one to the exact production firmware installed on my gateway, so I am NOT claiming that any specific public RDK issue is definitely causing this.
However, some recent public RDK Central OneWifi work seems relevant enough to mention:
- XB10-2224:
RSNO2 element missing in beacon frames when WPA3 Compatibility Mode is enabled.
- RDKB-59476:
WPA3-Compatibility not persisting on reboot.
- RDKB-59745:
Support for client roaming from WPA3-P to WPA2-P.
- RDKB-64957:
Observed WPA2-Personal security mode configuration failure.
There is also a recent Xfinity Community post dated September 8, 2026 involving an XB10 and a Galaxy S24 Ultra where the device could see a WPA3-Personal-Transition SSID but repeatedly reported "Couldn't connect to network."
In that case, splitting the bands resolved the issue.
My case differs because splitting the bands alone did NOT resolve the Shield 5 GHz failure. Both Shields still refused the isolated XB10 5 GHz network until its security mode was changed from WPA3-Personal-Transition to WPA2.
Xfinity's current security documentation also notes that there are rare cases in which older clients may not connect correctly when WPA3-Personal-Transition is enabled.
POSSIBLY RELATED OBSERVATION
I have also been testing a 2.4 GHz Wi-Fi smart lock.
That device has had considerably more difficulty connecting reliably to the Xfinity gateway directly than through the older Netgear WPA2 repeater.
I am not claiming this has the same root cause, but I am mentioning it because the behavior may be relevant if there is a broader XB10 interoperability issue.
DOCSIS / WAN SIDE
I also checked the cable side.
- All downstream channels were locked
- Downstream SNR was approximately 41.3-43.6 dB
- Downstream power was approximately +9.5 to +12.6 dBmV
- All six upstream channels were locked
- Upstream power was approximately 35.3-36.5 dBmV
- Zero downstream uncorrectable codewords were shown
- Internet status was Active
The failure occurs during Wi-Fi association and is immediately changed by the Wi-Fi security mode, so I do not believe this is a DOCSIS/WAN issue. I am including those values for completeness.
WHAT I WOULD LIKE XFINITY TO CHECK
Could someone please check the following?
1. Is CGM601TCOM_8.5p12s6_PROD_sey the current production firmware for this Technicolor XB10 hardware revision 3.0 on my account/market?
2. Did this gateway receive any firmware, OneWifi, WebConfig, security, optimization or other remote configuration change around September 16-17?
3. Can the XB10 / OneWifi / hostapd association logs be checked for the failed NVIDIA Shield 5 GHz connection attempts and the actual authentication/association failure reason?
4. Is the current XB10 5 GHz WPA3-Personal-Transition configuration known to have interoperability issues involving RSN/RSNO2, SAE, PMF, CCMP/GCMP/GCMP-256 or other capabilities with established 802.11ac clients?
5. Can Xfinity explain why the app temporarily reported WPA2 while the local gateway interface reported WPA3-Personal-Transition, followed later by the app also returning to WPA3-Personal-Transition without me intentionally changing it?
6. Can the gateway's OneWifi/private-VAP configuration be reprovisioned or rebuilt from the Xfinity side, and is there a newer production build available if this is a known issue?
7. If the current XB10 cannot reliably provide WPA3-Personal-Transition compatibility to these clients, should the gateway be exchanged or escalated to the XB10/Wi-Fi engineering team?
I am happy to provide approximate timestamps or additional diagnostic information privately to an Xfinity employee.
I would prefer not to factory-reset both NVIDIA Shields because:
- Two independent Shields reproduce the same failure
- Both connect to other access points
- The Shields can use 5 GHz elsewhere
- The XB10's 5 GHz radio works with my phone
- Both Shields connect to XB10 5 GHz immediately when only the security mode is changed to WPA2
At this point I believe the evidence warrants investigation of the XB10's WPA3-Personal-Transition / 5 GHz association behavior rather than treating this as two simultaneous Shield hardware failures.



No Responses!