L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translation
No sign of exploitation. No public exploitation artifact known so far.
This vulnerability allows attackers to bypass network security filters (like IPv6 RA guard) by crafting specially malformed network frames during Ethernet to WiFi conversion. An attacker on the network can send packets that appear legitimate to the filter but contain hidden malicious content.
The vulnerability exploits improper frame translation during Ethernet-to-WiFi conversion where LLC/SNAP headers with invalid lengths combined with optional VLAN0 stacking can evade Layer 2 filtering mechanisms. Attack requires network access and relies on the device mishandling malformed header fields during frame conversion, potentially bypassing RA guard and similar L2 security controls.