CVE-2020-26143 is a vulnerability in the ALFA Windows 10 driver for AWUS036ACH, affecting Wi-Fi implementations in products from Alfa, Arista, and Siemens. It allows an attacker on the same network to inject arbitrary data frames into protected Wi-Fi networks (WEP, WPA, WPA2, WPA3) by exploiting the acceptance of fragmented plaintext frames. With a CVSS score of 6.5 (Medium), this vulnerability requires adjacent network access and has a high impact on integrity, but no impact on confidentiality or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit or ExploitDB. Despite limited community discussion, the vulnerability has received media coverage due to its relation to the broader FragAttacks vulnerabilities.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1030.36.604CPE matchmatch criteria | cpe:2.3:o:alfa:awus036h_firmware:1030.36.604:*:*:*:*:windows_10:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:c-75_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:o-90_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:c-65_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:arista:w-68_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.