CVE-2020-26140

An issue was discovered in the ALFA Windows 10 driver 6.1316.1209 for AWUS036H. The WEP, WPA, WPA2, and WPA3 implementations accept plaintext frames in a protected Wi-Fi network. An adversary can abuse this to inject arbitrary data frames independent of the network configuration.

Published: 2021-05-11 Last update: 2026-04-14 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2020-26140 is rated Low Risk (39.7/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.18%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2020-26140

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-03-04 0.09% 0.18% +0.09%
2 2026-03-01 0.18% 0.09% -0.09%
3 2026-02-04 0.18%

Full EPSS history (37 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2020-26140

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.5 3.1 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Click to expand
Attack vector (AV:A)
Attacker has to be nearby on the network—same office, same link, that vibe—not the whole wide internet.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 3.6 [email protected]
3.3 2.0 LOW
AV:A/AC:L/Au:N/C:N/I:P/A:N Click to expand
Access vector (AV:A)
Requires access to an adjacent network segment.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:N)
No availability impact.
6.5 2.9 [email protected]

Weakness enumeration for CVE-2020-26140

OS Trackers for CVE-2020-26140

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2020-26140
suse high CVE-2020-26140 severity important: SUSE including 32 source package names (bpftool-4.18.0-348.el8, kernel-4.18.0-348.el8, …), 81 product×package rows across 21 product lines (SUSE Liberty Linux 8, SUSE Linux Enterprise High Performance Computing 15-LTSS, … (21 product lines)): Known Not Affected 61, Fixed 20. https://www.suse.com/security/cve/CVE-2020-26140/
ubuntu medium CVE-2020-26140 medium priority: Ubuntu including 168 source packages (linux, linux-allwinner, …), 2155 status rows across 16 suites (bionic, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): DNE 1686, ignored 307, needs-triage 162. https://ubuntu.com/security/CVE-2020-26140

Affected software / configurations for CVE-2020-26140

Vendor Product Version Raw CPE
alfa awus036h_firmware 6.1316.1209 cpe:2.3:o:alfa:awus036h_firmware:6.1316.1209:*:*:*:*:windows_10:*:*
siemens scalance_w1748-1_firmware cpe:2.3:o:siemens:scalance_w1748-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w1750d_firmware cpe:2.3:o:siemens:scalance_w1750d_firmware:-:*:*:*:*:*:*:*
siemens scalance_w1788-1_firmware cpe:2.3:o:siemens:scalance_w1788-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w1788-2_firmware cpe:2.3:o:siemens:scalance_w1788-2_firmware:-:*:*:*:*:*:eec_m12:*
siemens scalance_w1788-2_firmware cpe:2.3:o:siemens:scalance_w1788-2_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w1788-2ia_firmware cpe:2.3:o:siemens:scalance_w1788-2ia_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w721-1_firmware cpe:2.3:o:siemens:scalance_w721-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w722-1_firmware cpe:2.3:o:siemens:scalance_w722-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w734-1_firmware cpe:2.3:o:siemens:scalance_w734-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w738-1_firmware cpe:2.3:o:siemens:scalance_w738-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w748-1_firmware cpe:2.3:o:siemens:scalance_w748-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w748-1_firmware cpe:2.3:o:siemens:scalance_w748-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w761-1_firmware cpe:2.3:o:siemens:scalance_w761-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w774-1_firmware cpe:2.3:o:siemens:scalance_w774-1_firmware:-:*:*:*:*:*:m12_eec:*
siemens scalance_w774-1_firmware cpe:2.3:o:siemens:scalance_w774-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w778-1_firmware cpe:2.3:o:siemens:scalance_w778-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w778-1_firmware cpe:2.3:o:siemens:scalance_w778-1_firmware:-:*:*:*:*:*:m12_eec:*
siemens scalance_w786-1_firmware cpe:2.3:o:siemens:scalance_w786-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w786-2_firmware cpe:2.3:o:siemens:scalance_w786-2_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w786-2_firmware cpe:2.3:o:siemens:scalance_w786-2_firmware:-:*:*:*:*:*:sfp:*
siemens scalance_w786-2ia_firmware cpe:2.3:o:siemens:scalance_w786-2ia_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w788-1_firmware cpe:2.3:o:siemens:scalance_w788-1_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w788-1_firmware cpe:2.3:o:siemens:scalance_w788-1_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_w788-2_firmware cpe:2.3:o:siemens:scalance_w788-2_firmware:-:*:*:*:*:*:m12:*
siemens scalance_w788-2_firmware cpe:2.3:o:siemens:scalance_w788-2_firmware:-:*:*:*:*:*:m12_eec:*
siemens scalance_w788-2_firmware cpe:2.3:o:siemens:scalance_w788-2_firmware:-:*:*:*:*:*:rj45:*
siemens scalance_wam763-1_firmware cpe:2.3:o:siemens:scalance_wam763-1_firmware:-:*:*:*:*:*:*:*
siemens scalance_wam766-1_firmware cpe:2.3:o:siemens:scalance_wam766-1_firmware:-:*:*:*:*:*:*:*
siemens scalance_wam766-1_firmware cpe:2.3:o:siemens:scalance_wam766-1_firmware:-:*:*:*:*:*:eec:*
siemens scalance_wam766-1_6ghz_firmware cpe:2.3:o:siemens:scalance_wam766-1_6ghz_firmware:-:*:*:*:*:*:*:*
siemens scalance_wam766-1_6ghz_firmware cpe:2.3:o:siemens:scalance_wam766-1_6ghz_firmware:-:*:*:*:*:*:eec:*
siemens scalance_wum763-1_firmware cpe:2.3:o:siemens:scalance_wum763-1_firmware:-:*:*:*:*:*:*:*
siemens scalance_wum766-1_firmware cpe:2.3:o:siemens:scalance_wum766-1_firmware:-:*:*:*:*:*:*:*
siemens scalance_wum766-1_6ghz_firmware cpe:2.3:o:siemens:scalance_wum766-1_6ghz_firmware:-:*:*:*:*:*:*:*
arista c-100_firmware cpe:2.3:o:arista:c-100_firmware:-:*:*:*:*:*:*:*
arista c-110_firmware cpe:2.3:o:arista:c-110_firmware:-:*:*:*:*:*:*:*
arista c-120_firmware cpe:2.3:o:arista:c-120_firmware:-:*:*:*:*:*:*:*
arista c-130_firmware cpe:2.3:o:arista:c-130_firmware:-:*:*:*:*:*:*:*
arista c-200_firmware cpe:2.3:o:arista:c-200_firmware:-:*:*:*:*:*:*:*
arista c-230_firmware cpe:2.3:o:arista:c-230_firmware:-:*:*:*:*:*:*:*
arista c-235_firmware cpe:2.3:o:arista:c-235_firmware:-:*:*:*:*:*:*:*
arista c-250_firmware cpe:2.3:o:arista:c-250_firmware:-:*:*:*:*:*:*:*
arista c-260_firmware cpe:2.3:o:arista:c-260_firmware:-:*:*:*:*:*:*:*
arista c-65_firmware cpe:2.3:o:arista:c-65_firmware:-:*:*:*:*:*:*:*
arista c-75_firmware cpe:2.3:o:arista:c-75_firmware:-:*:*:*:*:*:*:*
arista o-105_firmware cpe:2.3:o:arista:o-105_firmware:-:*:*:*:*:*:*:*
arista o-90_firmware cpe:2.3:o:arista:o-90_firmware:-:*:*:*:*:*:*:*
arista w-118_firmware cpe:2.3:o:arista:w-118_firmware:-:*:*:*:*:*:*:*
arista w-68_firmware cpe:2.3:o:arista:w-68_firmware:-:*:*:*:*:*:*:*
cisco 1100_firmware cpe:2.3:o:cisco:1100_firmware:-:*:*:*:*:*:*:*
cisco 1100-4p_firmware cpe:2.3:o:cisco:1100-4p_firmware:-:*:*:*:*:*:*:*
cisco 1100-8p_firmware cpe:2.3:o:cisco:1100-8p_firmware:-:*:*:*:*:*:*:*
cisco 1101-4p_firmware cpe:2.3:o:cisco:1101-4p_firmware:-:*:*:*:*:*:*:*
cisco 1109-2p_firmware cpe:2.3:o:cisco:1109-2p_firmware:-:*:*:*:*:*:*:*
cisco 1109-4p_firmware cpe:2.3:o:cisco:1109-4p_firmware:-:*:*:*:*:*:*:*
cisco aironet_1532_firmware cpe:2.3:o:cisco:aironet_1532_firmware:-:*:*:*:*:*:*:*
cisco aironet_1542d_firmware cpe:2.3:o:cisco:aironet_1542d_firmware:-:*:*:*:*:*:*:*
cisco aironet_1542i_firmware cpe:2.3:o:cisco:aironet_1542i_firmware:-:*:*:*:*:*:*:*
cisco aironet_1552_firmware cpe:2.3:o:cisco:aironet_1552_firmware:-:*:*:*:*:*:*:*
cisco aironet_1552h_firmware cpe:2.3:o:cisco:aironet_1552h_firmware:-:*:*:*:*:*:*:*
cisco aironet_1560_firmware cpe:2.3:o:cisco:aironet_1560_firmware:-:*:*:*:*:*:*:*
cisco aironet_1562d_firmware cpe:2.3:o:cisco:aironet_1562d_firmware:-:*:*:*:*:*:*:*
cisco aironet_1562e_firmware cpe:2.3:o:cisco:aironet_1562e_firmware:-:*:*:*:*:*:*:*
cisco aironet_1562i_firmware cpe:2.3:o:cisco:aironet_1562i_firmware:-:*:*:*:*:*:*:*
cisco aironet_1572_firmware cpe:2.3:o:cisco:aironet_1572_firmware:-:*:*:*:*:*:*:*
cisco aironet_1702_firmware cpe:2.3:o:cisco:aironet_1702_firmware:-:*:*:*:*:*:*:*
cisco aironet_1800_firmware cpe:2.3:o:cisco:aironet_1800_firmware:-:*:*:*:*:*:*:*
cisco aironet_1800i_firmware cpe:2.3:o:cisco:aironet_1800i_firmware:-:*:*:*:*:*:*:*
cisco aironet_1810_firmware cpe:2.3:o:cisco:aironet_1810_firmware:-:*:*:*:*:*:*:*
cisco aironet_1810w_firmware cpe:2.3:o:cisco:aironet_1810w_firmware:-:*:*:*:*:*:*:*
cisco aironet_1815_firmware cpe:2.3:o:cisco:aironet_1815_firmware:-:*:*:*:*:*:*:*
cisco aironet_1815i_firmware cpe:2.3:o:cisco:aironet_1815i_firmware:-:*:*:*:*:*:*:*
cisco aironet_1832_firmware cpe:2.3:o:cisco:aironet_1832_firmware:-:*:*:*:*:*:*:*
cisco aironet_1842_firmware cpe:2.3:o:cisco:aironet_1842_firmware:-:*:*:*:*:*:*:*
cisco aironet_1852_firmware cpe:2.3:o:cisco:aironet_1852_firmware:-:*:*:*:*:*:*:*
cisco aironet_2702_firmware cpe:2.3:o:cisco:aironet_2702_firmware:-:*:*:*:*:*:*:*
cisco aironet_2800_firmware cpe:2.3:o:cisco:aironet_2800_firmware:-:*:*:*:*:*:*:*
cisco aironet_2800e_firmware cpe:2.3:o:cisco:aironet_2800e_firmware:-:*:*:*:*:*:*:*
cisco aironet_2800i_firmware cpe:2.3:o:cisco:aironet_2800i_firmware:-:*:*:*:*:*:*:*

References for CVE-2020-26140

cvelogic Threat Intelligence