An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-18773 An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 02 Jun 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Apr 2026 09:30:00 +0000


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-06-02T13:53:46.824Z

Reserved: 2020-09-29T00:00:00.000Z

Link: CVE-2020-26146

cve-icon Vulnrichment

Updated: 2024-08-04T15:49:07.202Z

cve-icon NVD

Status : Modified

Published: 2021-05-11T20:15:08.907

Modified: 2026-06-17T03:07:42.170

Link: CVE-2020-26146

cve-icon Redhat

Severity : Low

Publid Date: 2021-05-11T00:00:00Z

Links: CVE-2020-26146 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses