← back
CVE-2021-27862mediumCWE-130CWE-290

L2 network filtering bypass using stacked VLAN0 and LLC/SNAP headers with an invalid length during Ethernet to Wifi frame translation

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 4.7epss 0.6%
exploitation probability
0.6%top 53% of all CVEs
observed exploitation
nono source reports it
In short

This vulnerability allows attackers to bypass network security filters (like IPv6 RA guard) by crafting specially malformed network frames during Ethernet to WiFi conversion. An attacker on the network can send packets that appear legitimate to the filter but contain hidden malicious content.

Technical detail

The vulnerability exploits improper frame translation during Ethernet-to-WiFi conversion where LLC/SNAP headers with invalid lengths combined with optional VLAN0 stacking can evade Layer 2 filtering mechanisms. Attack requires network access and relies on the device mishandling malformed header fields during frame conversion, potentially bypassing RA guard and similar L2 security controls.

Summary generated and translated by AI from the official description.
Layer 2 network filtering capabilities such as IPv6 RA guard can be bypassed using LLC/SNAP headers with invalid length and Ethernet to Wifi frame conversion (and optionally VLAN0 headers).
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N