CVE-2020-26146 - CVE House
Back to Database
Status published Unknown CVE-2020-26146

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4...

Vulnerability Description

An issue was discovered on Samsung Galaxy S3 i9305 4.4.4 devices. The WPA, WPA2, and WPA3 implementations reassemble fragments with non-consecutive packet numbers. An adversary can abuse this to exfiltrate selected fragments. This vulnerability is exploitable when another device sends fragmented frames and the WEP, CCMP, or GCMP data-confidentiality protocol is used. Note that WEP is vulnerable to this attack by design.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-26146

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

galaxy i9305 firmware, c-250 firmware, c-260 firmware, c-230 firmware, c-235 firmware, c-200 firmware, c-120 firmware, c-130 firmware, c-100 firmware, c-110 firmware, o-105 firmware, w-118 firmware, c-75 firmware, o-90 firmware, c-65 firmware, w-68 firmware, scalance w700 ieee 802.11n firmware, scalance w1700 ieee 802.11ac firmware, scalance w1750d firmware
Vulnerable Versions:
4.4.4, 0

Timeline

Official Publish: May 11th, 2021
Last Modified: June 2nd, 2026
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.