Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.61%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 11
Latest updateMay 24

Description

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages1 packages

NVDalfa/awus036h_firmware6.1316.1209

🔴Vulnerability Details

3
GHSA
GHSA-px4f-q3pw-j682: An issue was discovered in the ALFA Windows 10 driver 62022-05-24
OSV
CVE-2020-26140: An issue was discovered in the ALFA Windows 10 driver 62021-05-11
CVEList
CVE-2020-26140: An issue was discovered in the ALFA Windows 10 driver 62021-05-11

📋Vendor Advisories

3
Android
CVE-2020-26140: Closed-source component2021-10-01
Red Hat
kernel: accepting plaintext data frames in protected networks2021-05-11
Cisco
Multiple Vulnerabilities in Frame Aggregation and Fragmentation Implementations of 802.11 Specification Affecting Cisco Products: May 20212021-05-11

💬Community

1
HackerOne
Fragmentation and Aggregation Flaws in Wi-Fi2021-07-23
CVE-2020-26140 — Alfa Awus036h Firmware vulnerability | cvebase