CVE-2019-18991: Qualcomm Atheros AR9132 Firmware

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

A partial authentication bypass vulnerability exists on Atheros AR9132 3.60(AMX.8), AR9283 1.85, and AR9285 1.0.0.12NA devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

Affected products

  • Qualcomm Atheros AR9132 Firmware: version 3.60(amx.8) only
  • Qualcomm Atheros AR9283 Firmware: version 1.85 only
  • Qualcomm Atheros AR9285 Firmware: version 1.0.0.12na only

Published 2020-09-30. Last modified 2026-06-17.