CVE-2022-47522 is a Wi-Fi encryption bypass issue arising from IEEE 802.11 specifications through 802.11ax. A physically proximate attacker can spoof a target station's MAC address, send Power Save signaling to cause an access point to buffer frames for the victim, and then trigger removal of the victim's original security context by sending additional management frames such as authentication or reassociation frames. Because the specification does not require the access point to purge its transmit queue before removing the client's pairwise encryption key, buffered target-destined unicast frames may subsequently be transmitted under a less restrictive keying context. In affected implementations, this can expose victim-destined traffic that should have remained protected under the victim's pairwise key.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a full proof-of-concept (PoC) exploit for CVE-2022-47522, a vulnerability in Wi-Fi networks that allows an attacker to bypass client isolation and intercept frames intended for other clients. The exploit targets Wi-Fi networks where Management Frame Protection (MFP) is disabled. The attack works by disconnecting a victim client from the network, then quickly reconnecting as the victim (using the victim's MAC address) before the AP delivers pending frames, thus allowing the attacker to receive those frames. The repository is structured into two main components: the 'attacker' directory, which contains Python scripts and configuration files for executing the attack, and the 'macstealer' directory, which contains supporting code, documentation, and build scripts for Wi-Fi tools (including hostapd and wpa_supplicant). The main exploit logic is implemented in 'attacker/attacker.py', which automates the attack steps: pre-connection, MAC address spoofing, deauthentication, and frame interception. The repository also includes extensive documentation, build instructions, and example configurations for both attacker and victim environments. The exploit is operational and can be used to demonstrate the vulnerability in real-world Wi-Fi networks with the required setup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.