CVE-2020-26141 is a medium-severity vulnerability affecting the ALFA Windows 10 driver for AWUS036H, and potentially other Wi-Fi devices from vendors like Cisco and Siemens. The flaw lies in the Wi-Fi implementation's failure to verify the Message Integrity Check of fragmented TKIP frames, allowing an adjacent attacker to inject and potentially decrypt packets in WPA/WPA2 networks utilizing TKIP. With a CVSS score of 6.5, this vulnerability has a low attack complexity and can lead to high integrity impact without user interaction. While not listed in CISA's KEV catalog, and with no public exploit code (Metasploit, Nuclei, ExploitDB) available, it has garnered some community discussion and media coverage as part of the broader "FragAttacks" disclosures.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1316.1209CPE matchmatch criteria | cpe:2.3:o:alfa:awus036h_firmware:6.1316.1209:*:*:*:*:windows_10:*:* | ||
< 27.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_gr10_firmware:*:*:*:*:*:*:*:* | ||
< 27.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_gr60_firmware:*:*:*:*:*:*:*:* | ||
< 27.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mr20_firmware:*:*:*:*:*:*:*:* | ||
< 27.7.1CPE matchmatch criteria | cpe:2.3:o:cisco:meraki_mr30h_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.