CVE-2026-23809
- EPSS 0.03%
- Veröffentlicht 04.03.2026 16:10:02
- Zuletzt bearbeitet 09.03.2026 19:22:51
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSI...
CVE-2026-23808
- EPSS 0.08%
- Veröffentlicht 04.03.2026 16:09:17
- Zuletzt bearbeitet 09.03.2026 19:24:57
A vulnerability has been identified in a standardized wireless roaming protocol that could enable a malicious actor to install an attacker-controlled Group Temporal Key (GTK) on a client device. Successful exploitation of this vulnerability could all...
CVE-2026-23601
- EPSS 0.01%
- Veröffentlicht 04.03.2026 16:07:42
- Zuletzt bearbeitet 09.03.2026 19:25:46
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Suc...
CVE-2025-37179
- EPSS 0.08%
- Veröffentlicht 13.01.2026 20:08:58
- Zuletzt bearbeitet 23.01.2026 15:21:57
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory ...
CVE-2025-37178
- EPSS 0.08%
- Veröffentlicht 13.01.2026 20:08:23
- Zuletzt bearbeitet 23.01.2026 16:06:12
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory ...
CVE-2025-37177
- EPSS 0.12%
- Veröffentlicht 13.01.2026 20:08:06
- Zuletzt bearbeitet 23.01.2026 16:10:10
An arbitrary file deletion vulnerability has been identified in the command-line interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation of this vulnerability could allow an authenticated remote mali...
CVE-2025-37176
- EPSS 0.07%
- Veröffentlicht 13.01.2026 20:07:50
- Zuletzt bearbeitet 23.01.2026 16:12:02
A command injection vulnerability in AOS-8 allows an authenticated privileged user to alter a package header to inject shell commands, potentially affecting the execution of internal operations. Successful exploit could allow an authenticated malicio...
CVE-2025-37175
- EPSS 0.08%
- Veröffentlicht 13.01.2026 20:07:34
- Zuletzt bearbeitet 23.01.2026 16:37:56
Arbitrary file upload vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to upload arbitrary files a...
CVE-2025-37174
- EPSS 0.08%
- Veröffentlicht 13.01.2026 20:05:33
- Zuletzt bearbeitet 23.01.2026 16:38:12
Authenticated arbitrary file write vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor to create or m...
CVE-2025-37173
- EPSS 0.12%
- Veröffentlicht 13.01.2026 20:04:57
- Zuletzt bearbeitet 23.01.2026 16:44:30
An improper input handling vulnerability exists in the web-based management interface of mobility conductors running either AOS-10 or AOS-8 operating systems. Successful exploitation could allow an authenticated malicious actor with valid credentials...