6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
Researchers at Pennsylvania State University and Idaho National Laboratory have identified significant security vulnerabilities within 6 GHz Wi-Fi Automated Frequency Coordination (AFC) systems. These flaws could allow attackers to spoof location data, manipulate time synchronization, and cause widespread interference with critical infrastructure, including radio towers and cellular backhaul. While no active attacks have been identified, the potential for misuse and unintentional disruption is substantial, and the researchers are urging vendors to address these issues before they become a wider problem. The research will be presented at Black Hat USA 2026.
Researchers from Pennsylvania State University and Idaho National Laboratory have identified significant security vulnerabilities within 6 GHz Wi-Fi Automated Frequency Coordination (AFC) systems. These flaws could allow attackers to spoof location data, manipulate time synchronization, and cause widespread interference with critical infrastructure, including radio towers and cellular backhaul. While no active attacks have been identified, the potential for misuse and unintentional disruption is substantial, and the researchers are urging vendors to address these issues before they become a wider problem.
At the core of the issue are AFC systems, which regulate the 6 GHz band to prevent interference with radio towers, cellular backhaul, and spectrum-adjacent public safety networks. The researchers found that these systems by default trust client-side data, such as GPS, Global Navigation Satellite System (GNSS), Wi-Fi-based location data, DNS responses, and Network Time Protocol (NTP) time synchronization. An attacker could manipulate these inputs to cause an AP to report a false location to the AFC server, potentially obtaining unauthorized channel and power assignments.
Furthermore, the research demonstrates that an attacker could trigger a denial-of-service attack by spoofing locations outside supported regions, manipulating time synchronization, poisoning DNS lookups, and preventing APs from receiving valid AFC authorizations, potentially disabling 6 GHz operation altogether. Even consumer-level 6-GHz devices can cause interference that leads to degradation in the channel and, in severe cases, can put a channel into an unusable state.
The team emphasizes that these vulnerabilities aren't necessarily due to malicious intent; unintentional misuse by consumers seeking to expand AP coverage could inadvertently cause interference. Vendors have received mixed reactions to the research, with some acknowledging the issues and expressing a willingness to consider changes, while others have been more hesitant, citing concerns about usability and cost-efficiency.
The research will be presented at Black Hat USA 2026, August 1, 2026 TO August 6, 2026 at the Mandalay Bay Convention Center in Las Vegas, USA. Attendees can save $200 on a Briefings pass or $100 on a Business pass using code: DARKREADING.
