CVE-2026-21367 is a denial-of-service vulnerability affecting wireless network devices during the initial scan process, specifically triggered by processing FILS Discovery Frames with invalid action sizes that cause transient service disruption. The vulnerability carries a CVSS score of 7.6 (HIGH) with a network-based attack vector, though exploitation requires high privilege levels and user interaction, limiting its practical threat surface. The potential impact is significant, affecting confidentiality, integrity, and availability of the affected system, though the transient nature suggests temporary rather than permanent compromise. No evidence of active exploitation exists, with an EPSS score of 0.00031 indicating minimal real-world exploitation activity and no current inclusion on vulnerability alert lists. The moderate FAUCET Risk Score of 48.0 suggests organizations should address this vulnerability in their patching cycles, though it does not represent an immediate critical threat requiring emergency response.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:ar8035_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:cologne_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:csr8811_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6200_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:qualcomm:fastconnect_6700_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.