#VU114098 Insufficient verification of data authenticity in IEEE 802.11 - CVE-2025-27558
Published: August 15, 2025
IEEE 802.11
IEEE
Description
The vulnerability allows an attacker to perform spoofing attack.
The vulnerability exists due to insufficient verification of data authenticity in mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP). A remote attacker on the local network can inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames and perform spoofing attack.