← volver
CVE-2026-23601mediumCWE-327

Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise

13Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 5.4epss 0.1%
probabilidad de explotación
0.1%top 100% de las CVE
explotación observada
noninguna fuente lo reporta
A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N