A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
History

Wed, 04 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in the wireless encryption handling of Wi-Fi transmissions. A malicious actor can generate shared-key authenticated transmissions containing targeted payloads while impersonating the identity of a primary BSSID.Successful exploitation allows for the delivery of tampered data to specific endpoints, bypassing standard cryptographic separation.
Title Frame Injection via Shared GTK Allows Traffic Spoofing and Client Compromise
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: hpe

Published:

Updated: 2026-03-04T17:59:28.741Z

Reserved: 2026-01-14T15:40:17.991Z

Link: CVE-2026-23601

cve-icon Vulnrichment

Updated: 2026-03-04T17:56:17.146Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-04T17:16:18.610

Modified: 2026-03-04T19:16:19.147

Link: CVE-2026-23601

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.