CVE-2019-18991: Qualcomm Atheros AR9132 Firmware
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
Affected products
- Qualcomm Atheros AR9132 Firmware: version 3.60(amx.8) only
- Qualcomm Atheros AR9283 Firmware: version 1.85 only
- Qualcomm Atheros AR9285 Firmware: version 1.0.0.12na only
Published 2020-09-30. Last modified 2026-06-17.