A serious software flaw in Broadcom's WiFi chipsets could allow an attacker within range of the radio to completely disrupt wireless connections by sending a single malicious frame, forcing routers to be manually rebooted to restore connectivity. The flaw, discovered by Black Duck during fuzzing tests of 802.11 protocol, affects 5GHz wireless networks and causes all connected clients, including guest networks, to disconnect simultaneously.
See also: Broadcom: Cl0p breach via zero-day in Oracle EBS?

“Protocol implementation-level bugs, like 802.11, are often harder to detect than cryptographic weaknesses,” said Ben Ronallo, principal cybersecurity engineer at Black Duck. “Remediating vulnerabilities in hardware/software is always slower because of the impact that needs to be fully tested. In the software world, the typical timeframe is 90 days, but for hardware or software it’s closer to 180+ days.”
The issue emerged while researchers were testing ASUS routers for protocol resilience, but further investigation traced the cause to software used in Broadcom chipsets rather than the router software itself. Broadcom has since issued an update to its customers and ASUS has released patched software for affected devices, although a full public list of affected products remains unavailable.
Broadcom did not immediately respond to the CSO’s request for comment. According to the notice shared with the CSO before its publication on Tuesday, the exploit requires no authentication and operates independently of the wireless network’s security settings. An attacker only needs to be within range to transmit a specially crafted 802.11 frame, instantly rendering the access point unresponsive to all clients in the 5 GHz band.
Devices cannot reconnect until the router is manually rebooted, at which point the attack can be repeated indefinitely. James Maude, field CTO at BeyondTrust, said the findings are reminiscent of early WiFi attacks that relied on de-authentication and denial-of-service (DoS) tactics.
See also: CISA warns of vulnerability in VMware Tools and Aria Operations

Maude warned that repeated outages could also enable “evil twin” scenarios, where a malicious access point impersonates the legitimate network and tricks users into entering credentials through captive portals.
The good news, Maude added, is that the bug appears to be limited to 5GHz networks, meaning many environments can automatically fall back to 2.4GHz connectivity, reducing immediate exposure. CyRC gave the vulnerability a CVSS 4.0 score of 8.4 (high), primarily due to its impact on availability rather than loss of confidentiality or data integrity. The testing was conducted using an ASUS RT-BE86U with software versions 3.0.0.6.102_37812 and older, although the advisory warned that other devices using the same chipset software could be similarly affected.
The researchers said the vulnerability highlights why the protocol implementation remains open to serious bugs. “This attack is both easy to execute and highly disruptive, highlighting that even mature and widely deployed network technologies can still yield new and serious attack vectors,” said Saumitra Das, vice president of engineering at Qualys.
Broadcom's PSIRT reportedly confirmed that it has released a patched version of the affected software to customers, with device manufacturers expected to incorporate the fix into their own software distributions. ASUS has also released a patch in software version 3.0.0.6.102_37841 and later. CyRC stated that specific technical details of the vulnerability were intentionally withheld due to the risk of widespread exploitation across the wireless infrastructure.
See also: OpenAI and Broadcom will produce their own AI chips

Recommendations include segmenting wireless networks, inspecting for access points that have reached end-of-life, prioritizing repairs based on business criticality, and closely monitoring network edges.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
