CVE-2026-23810: Cross-BSSID GTK Re-encryption and Traffic Injection
A vulnerability in the packet processing logic may allow an authenticated attacker to craft and transmit a malicious Wi-Fi frame that causes an Access Point (AP) to classify the frame as group-addressed traffic and re-encrypt it using the Group Temporal Key (GTK) associated with the victim's BSSID. Successful exploitation may enable GTK-independent traffic injection and, when combined with a port-stealing technique, allows an attacker to redirect intercepted traffic to facilitate machine-in-the-middle (MitM) attacks across BSSID boundaries.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23810?
The severity of CVE-2026-23810 is classified as high due to the potential for traffic injection and security breaches.
How do I fix CVE-2026-23810?
To fix CVE-2026-23810, upgrade your ArubaOS to the latest patched version as recommended by Aruba Networks.
What systems are affected by CVE-2026-23810?
CVE-2026-23810 affects multiple versions of ArubaOS, specifically from version 6.5.4.0 to 10.8.0.0.
What type of attack can CVE-2026-23810 enable?
CVE-2026-23810 can enable authenticated attackers to perform traffic injection attacks and manipulate network communications.
Is CVE-2026-23810 easy to exploit?
Exploitation of CVE-2026-23810 requires authenticated access, making it more challenging but still critical to address.