CVE-2026-23809

EUVD-2026-9415
A technique has been identified that adapts a known port-stealing method to Wi-Fi environments that use multiple BSSIDs. By leveraging the relationship between BSSIDs and their associated virtual ports, an attacker could potentially bypass inter-BSSID isolation controls. Successful exploitation may enable an attacker to redirect and intercept the victim's network traffic, potentially resulting in eavesdropping, session hijacking, or denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
arubanetworksarubaos
6.5.4.0 ≤
𝑥
≤ 8.10.0.21
arubanetworksarubaos
8.11.0.0 ≤
𝑥
≤ 8.12.0.6
arubanetworksarubaos
8.13.0.0 ≤
𝑥
≤ 8.13.1.1
arubanetworksarubaos
10.3.0.0 ≤
𝑥
≤ 10.4.1.10
arubanetworksarubaos
10.5.0.0 ≤
𝑥
≤ 10.7.2.2
arubanetworksarubaos
10.8.0.0
𝑥
= Vulnerable software versions