CVE-2026-23820
- EPSS 0.56%
- Veröffentlicht 12.05.2026 18:34:34
- Zuletzt bearbeitet 12.08.2026 18:41:30
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow an attacker...
CVE-2026-23819
- EPSS 0.27%
- Veröffentlicht 12.05.2026 18:31:33
- Zuletzt bearbeitet 11.08.2026 16:00:31
A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an unauthenticated remote attacker to execute arbitrary JavaScript code in a victim's browser within the same local network. Successfu...
CVE-2026-23812
- EPSS 0.15%
- Veröffentlicht 04.03.2026 16:13:48
- Zuletzt bearbeitet 09.03.2026 19:14:53
A vulnerability has been identified where an attacker connecting to an access point as a standard wired or wireless client can impersonate a gateway by leveraging an address-based spoofing technique. Successful exploitation enables the redirection of...
CVE-2026-23811
- EPSS 0.16%
- Veröffentlicht 04.03.2026 16:12:32
- Zuletzt bearbeitet 09.03.2026 19:19:27
A vulnerability in the client isolation mechanism may allow an attacker to bypass Layer 2 (L2) communication restrictions between clients and redirect traffic at Layer 3 (L3). In addition to bypassing policy enforcement, successful exploitation - whe...
CVE-2026-23810
- EPSS 0.18%
- Veröffentlicht 04.03.2026 16:11:35
- Zuletzt bearbeitet 09.03.2026 19:20:48
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Tempo...
CVE-2026-23809
- EPSS 0.26%
- Veröffentlicht 04.03.2026 16:10:02
- Zuletzt bearbeitet 09.03.2026 19:22:51
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSI...
CVE-2026-23808
- EPSS 0.26%
- Veröffentlicht 04.03.2026 16:09:17
- Zuletzt bearbeitet 09.03.2026 19:24:57
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could all...
CVE-2026-23601
- EPSS 0.08%
- Veröffentlicht 04.03.2026 16:07:42
- Zuletzt bearbeitet 09.03.2026 19:25:46
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Suc...
CVE-2025-37179
- EPSS 0.32%
- Veröffentlicht 13.01.2026 20:08:58
- Zuletzt bearbeitet 23.01.2026 15:21:57
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory ...
CVE-2025-37178
- EPSS 0.34%
- Veröffentlicht 13.01.2026 20:08:23
- Zuletzt bearbeitet 23.01.2026 16:06:12
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory ...