CVE-2022-20728Medium· 4.7▾ SunlitA vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device. This v…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 25.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CSAF
Last analysed / modified upstream
0.3%
A vulnerability in the client forwarding code of multiple Cisco Access Points (APs) could allow an unauthenticated, adjacent attacker to inject packets from the native VLAN to clients within nonnative VLANs on an affected device.
This vulnerability is due to a logic error on the AP that forwards packets that are destined to a wireless client if they are received on the native VLAN. An attacker could exploit this vulnerability by obtaining access to the native VLAN and directing traffic directly to the client through their MAC/IP combination. A successful exploit could allow the attacker to bypass VLAN separation and potentially also bypass any Layer 3 protection mechanisms that are deployed.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
Cisco Access Points VLAN Bypass from Native VLAN Vulnerability. Released 2022-09-27, updated 2022-10-04.
Affected:
Cisco has released software updates that address this vulnerability. https://software.cisco.com
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-20056Medium· 6.5Cisco Access Point Software Denial of Service
CVE-2021-1437High· 7.5Cisco Aironet Access Points FlexConnect Upgrade Information Disclosure Vulnerability (CVE-2021-1437)
CVE-2022-20622High· 8.6Cisco Aironet Access Points ICMP Denial of Service Vulnerability
CVE-2023-20097Medium· 4.6Cisco Access Points (AP) Command Injection Vulnerability
CVE-2023-20112High· 7.4Cisco Access Point Software Association Request Denial of Service Vulnerability (CVE-2023-20112)
CVE-2025-20364Medium· 4.3Cisco Wireless Access Point Software Device Analytics Action Frame Injection Vulnerability (CVE-2025-20364)