What is the HTB CWPE?
The HTB Certified Wi-Fi Pentesting Expert (CWPE) is Hack The Box's hands-on wireless penetration testing certification. It tests whether you can attack real-world Wi-Fi networks across WEP, WPA, WPA2, and WPA3, from cracking and evil-twin attacks through captive portals to a full corporate wireless-to-domain compromise, and write it up in a professional report.
You earn it by completing the Wi-Fi Penetration Tester Job-Role Path (10 modules, 170 sections, rated Hard) and then passing the exam. You have to finish 100% of the path before the exam unlocks.
The exam
The CWPE exam runs for 7 days in a dedicated cloud lab over VPN, so you need no Wi-Fi hardware of your own. A letter of engagement sets the scope, and you attack a real-world wireless environment, submitting flags as proof for each vulnerability you exploit. HTB has not published the exact pass mark.
You also submit a commercial-grade report within 7 days of entering the exam, in English, as a PDF or ZIP of 20 MB or less, based on HTB's template. An instructor grades both the points and the report. You get 2 attempts per voucher, and the free retake has to start within 14 days of your feedback. Results arrive within 20 business days.
The 10 modules in order
- Wi-Fi Fundamentals: Wi-Fi Penetration Testing Basics
- WPS & WEP Attacks: Attacking Wi-Fi Protected Setup (WPS) · Wired Equivalent Privacy (WEP) Attacks
- WPA, WPA2 & Evil Twins: Attacking WPA/WPA2 Wi-Fi Networks · Wi-Fi Evil Twin Attacks
- WPA3 & Captive Portals: Attacking WPA3 Wi-Fi Networks · Bypassing Wi-Fi Captive Portals
- Cracking & Tooling: Wi-Fi Password Cracking Techniques · Wi-Fi Penetration Testing Tools and Techniques
- Corporate Wi-Fi: Attacking Corporate Wi-Fi Networks
Top tips to prepare
- Finish the path first. The exam unlocks only after 100% of the Wi-Fi Penetration Tester path, so complete every module before you book. (JXoaT, HTB)
- Practice full attack chains. Rehearse a corporate Wi-Fi engagement end to end, from recon to domain compromise, like the last module. (JXoaT, HTB)
- Stay in scope and document. Read the letter of engagement, and write up each finding with remediation in the template as you go. (JXoaT, HTB)
- Get fluent with the tooling. Be quick with aircrack-ng capture, and with eaphammer and wifipumpkin3 for WPA-Enterprise and evil-twin attacks. (JXoaT, V0lk3n)
- Know the protocols cold. Study how WEP, WPA, WPA2, and WPA3 differ, since the path attacks all four. (armourinfosec)
The full list of tips is at the bottom of the Resource Library tab.
How to use this tracker
- Set your start date at the top. Every day's calendar date and your pace indicator are computed from it.
- Pick a timeline (25/30/40/50/55 days). They all cover the same curriculum, just packed into more or fewer days, and your progress carries across when you switch.
- Tick each task as you finish it. A day is marked complete when all its tasks are done.
- Use the Notes field on each day as a journal for networks and clients you found, handshakes and creds captured, and attacks to revisit.
- All progress is saved in your browser. Use Export backup regularly to keep a copy.
CWPE launched in 2026, so there are no exam-taker write-ups yet. Lean on the last module, Attacking Corporate Wi-Fi Networks, which runs a full engagement end to end, and practice the report in the provided template before you book.
This is an independent study aid and is not affiliated with or endorsed by Hack The Box. Always confirm current module counts, exam format, and pricing on the official HTB Academy site.
Built on and inspired by mattrfield's coae-study-tracker.