We detect you are using an unsupported browser. For the best experience, please visit the site using Chrome, Firefox, Safari, or Edge. X
Maximize Your Experience: Reap the Personalized Advantages by Completing Your Profile to Its Fullest. Update Here
Stay in the loop with the latest from Microchip. Update your profile while you are at it. Update Here
Complete your profile to access more resources. Update Here

Fragmentation and Aggregation Attacks (FragAttacks) Wi-Fi® Vulnerabilities

Overview


FragAttacks is a group of vulnerabilities in Wi-Fi standards related to frame aggregation and fragmentation. Exploitability depends on device role, configuration and implementation. While these vulnerabilities may allow an attacker within range to inject or manipulate packets, exploitation is complex in practice and does not bypass higher layer protections such as Transport Layer Security (TLS). 

Vulnerabilities Covered 


This page addresses the following FragAttacks‑related vulnerabilities identified by Common Vulnerabilities and Exposures (CVEs):

  • CVE-2020-26139: Forwarding Extensible Authentication Protocol over LAN (EAPOL) frames even though the sender is not yet authenticated (should only affect access points (APs)) 

  • CVE-2020-26140: Accepting plaintext data frames in a protected network

  • CVE-2020-26141: Not verifying the Temporal Key Integrity Protocol Message Integrity Check (TKIP MIC) of fragmented frames 

  • CVE-2020-26143: Accepting fragmented plaintext data frames in a protected network 

  • CVE-2020-26144: Accepting plaintext Aggregated MAC Service Data Unit (A-MSDU) frames that start with an RFC1042 header with EtherType EAPOL in an encrypted network

  • CVE-2020-26145: Accepting plaintext broadcast fragments as full frames in an encrypted network 

  • CVE-2020-26146: Reassembling encrypted fragments with non-consecutive packet numbers

  • CVE-2020-24586: Fragment cache attack (not clearing fragments from memory when (re)connecting to a network)

  • CVE-2020-24587: Mixed key attack (reassembling fragments encrypted under different keys) 

  • CVE-2020-24588: Aggregation attack (accepting Non-Secure Packet Processing (non-SPP) A-MSDU frames)

Note: Not all FragAttacks CVEs apply to every device type. Applicability depends on supported Wi-Fi features and implementation details. Refer to the table below for detailed mapping of vulnerabilities to specific software and associated hardware. 

Affected Products and Resolution


Last Updated: June 30, 2026

Software/FirmwareAssociated HardwareCVEResolution/Mitigation
ATWILC1000/3000 Linux Driver Firmware

ATWILC1000, ATWILC1000-IC

ATWILC3000, ATWILC3000-IC

CVE-2020-24586

CVE-2020-24587

CVE-2020-24588

CVE-2020-26139

CVE-2020-26140

CVE-2020-26143

CVE-2020-26144

CVE-2020-26146

CVE-2020-26147

Update to version 15.6 or later
ATWILC1000/ATWILC3000 RTOS Driver Firmware

ATWILC1000, ATWILC1000-IC

ATWILC3000, ATWILC3000-IC

CVE-2020-24586

CVE-2020-24588

CVE-2020-26140

CVE-2020-26143

CVE-2020-26144

CVE-2020-26146

CVE-2020-26147

Update to version 4.8.3 or later
ATWINC1500 Firmware

ATSAMW25H18

ATWINC1500, ATWIN1500-IC 
ATWINC1510, ATWINC1510-IC

CVE-2020-24588

CVE-2020-26140

CVE-2020-26143

CVE-2020-26144

CVE-2020-26146

CVE-2020-26147

Update to version 19.7.6 or later
ATWINC3400 FirmwareATWINC3400, ATWINC3400-IC

CVE-2020-24588

CVE-2020-26140

CVE-2020-26143

CVE-2020-26144

CVE-2020-26146

CVE-2020-26147

Update to version 1.4.3 or later
MPLAB® Harmony v3 wireless_wifi Repository

WFI32E04UC, WFI32E04UE

WFI32E03PC, WFI32E03UC, WFI32E03PE, WFI32E03UE

WFI32E02UC, WFI32E02UE

WFI32E01PC, WFI32E01UC, WFI32E01PE, WFI32E01UE

PIC32MZ2051W104132 PIC32MZ1025W104132

CVE-2020-24586

CVE-2020-24588

CVE-2020-26140

CVE-2020-26143

CVE-2020-26144

CVE-2020-26146

CVE-2020-26147

Update to version 3.6.1 or later

Products Not Listed


Only products listed in the Affected Products and Resolution section of this advisory are known to be affected by these vulnerabilities.

Reference Documentation 


Reference documentation includes the following third-party research materials:

Live Chat

Need Help?

Privacy Policy