Alfa produces a niche portfolio of wireless networking devices and firmware, including USB adapters and access points such as the AWUS036H and WiFi CampPro series, that occupy a specialized but prominent place in penetration-testing and wireless-security communities. Vulnerabilities affecting the vendor skew strongly toward critical severity and recur through memory-safety and cryptographic weakness classes—classic buffer overflows, stack-based overflows, improper input validation, and use of broken or risky cryptographic algorithms—that are characteristic of embedded wireless firmware with limited memory and processing constraints. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alfa over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-29047CRITICAL Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the hiddenIndex in the function StorageEditUser | Apr 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-29046CRITICAL Buffer Overflow vulnerability inALFA WiFi CampPro router ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the GAPSMinute3 key value | Apr 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-29045CRITICAL Buffer Overflow vulnerability in ALFA_CAMPRO-co-2.29 allows a remote attacker to execute arbitrary code via the newap_text_0 key value | Apr 17, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-45846HIGH ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the torrentsindex parameter in the formBTClinetSetting function. | May 8, 2025 | 8.8 | 24 | NO | NO |
CVE-2020-26143MEDIUM An issue was discovered in the ALFA Windows 10 driver 1030.36.604 for AWUS036ACH. The WEP, WPA, WPA2, and WPA3 implementations accept fragmented plaintext frames in a protected Wi- | May 11, 2021 | 6.5 | 24 | NO | NO |
CVE-2020-26141MEDIUM An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The Wi-Fi implementation does not verify the Message Integrity Check (authenticity) of fragmented TK | May 11, 2021 | 6.5 | 23 | NO | NO |
CVE-2020-26140MEDIUM An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. A | May 11, 2021 | 6.5 | 23 | NO | NO |
CVE-2025-45847MEDIUM ALFA AIP-W512 v3.2.2.2.3 was discovered to contain an authenticated stack overflow via the targetAPMac parameter in the formWsc function. | May 8, 2025 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alfa.
Media articles that mention a CVE ID that affects a product developed by Alfa — matched by CVE ID, not by vendor name.