Executive Summary
In July 2026, researchers from Pennsylvania State University and Idaho National Laboratory identified significant security vulnerabilities in Automated Frequency Coordination (AFC) systems, which manage the 6 GHz Wi-Fi spectrum to prevent interference with critical infrastructure. The study revealed that AFC systems inherently trust client-side data, such as GPS coordinates and time synchronization inputs, without adequate verification. This trust model exposes the systems to potential attacks where adversaries could spoof location data or manipulate time synchronization, leading to unauthorized spectrum access, harmful interference with incumbent services, or denial-of-service conditions for legitimate 6 GHz Wi-Fi users. (darkreading.com)
The findings underscore the urgent need for enhanced security measures in AFC systems, especially as the adoption of 6 GHz Wi-Fi expands. Without addressing these vulnerabilities, critical communication infrastructures remain at risk of disruption, highlighting the importance of implementing robust authentication and validation mechanisms within AFC architectures to safeguard against potential exploits.
Why This Matters Now
As the deployment of 6 GHz Wi-Fi accelerates, the identified vulnerabilities in AFC systems pose immediate risks to critical infrastructure. Addressing these security gaps is essential to prevent potential disruptions and ensure the reliable operation of both incumbent and new wireless services.
Attack Path Analysis
An attacker exploits the trust in client-reported data within Automated Frequency Coordination (AFC) systems by spoofing GPS signals to mislead Wi-Fi access points (APs) about their location. This manipulation allows the attacker to gain unauthorized frequency and power assignments, potentially interfering with critical incumbent services. The attacker may escalate privileges by exploiting the AFC system's reliance on unauthenticated client inputs, enabling further manipulation of frequency allocations. By propagating false location data across multiple APs, the attacker moves laterally to disrupt broader network segments. Establishing command and control, the attacker maintains persistent interference by continuously feeding false data to the AFC system. Exfiltration is not applicable in this context as the attack focuses on disruption rather than data theft. The impact includes significant disruption to critical communications and services due to unauthorized frequency use and interference.
Kill Chain Progression
Initial Compromise
Description
The attacker spoofs GPS signals to mislead Wi-Fi access points (APs) about their location, exploiting the AFC system's trust in client-reported data.
MITRE ATT&CK® Techniques
Adversary-in-the-Middle: Evil Twin
Adversary-in-the-Middle: DHCP Spoofing
Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay
System Network Connections Discovery
System Network Configuration Discovery
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor-supplied security patches.
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement network segmentation and control over network traffic.
Control ID: Pillar 3: Network and Environment
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
6 GHz Wi-Fi AFC vulnerabilities threaten cellular backhaul infrastructure and spectrum management, enabling location spoofing attacks that disrupt critical communications networks.
Public Safety
AFC system flaws could interfere with spectrum-adjacent public safety networks through unauthorized frequency allocations, compromising emergency communications and response capabilities.
Utilities
Critical infrastructure operations face interference risks from compromised AFC systems enabling GPS spoofing and unauthorized power assignments affecting operational technology networks.
Aviation/Aerospace
Radio observatories and aviation communication systems vulnerable to harmful interference from AFC exploitation, potentially disrupting navigation and safety-critical spectrum operations.
Sources
- 6 GHz Wi-Fi Flaws Could Disrupt Critical Systemshttps://www.darkreading.com/perimeter/6-ghz-wi-fi-flaws-disrupt-critical-systemsVerified
- On the Security of 6 GHz Automated Frequency Coordination (AFC)https://www.ndss-symposium.org/ndss-paper/auto-draft-696/Verified
- A Systematic Threat Analysis and Practical Attacks on Automated Frequency Coordination Systemshttps://www.usenix.org/conference/nsdi26/presentation/dongVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it can limit the attacker's ability to exploit trust in client-reported data within Automated Frequency Coordination (AFC) systems, thereby reducing the potential for unauthorized frequency and power assignments.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to manipulate APs with spoofed GPS data would likely be constrained, reducing the risk of unauthorized frequency assignments.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges through unauthenticated inputs would likely be limited, reducing unauthorized frequency assignments.
Control: East-West Traffic Security
Mitigation: The attacker's capacity to spread false data across APs would likely be restricted, limiting the scope of network disruption.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to sustain interference through continuous false data input would likely be diminished, reducing persistent disruption.
Control: Egress Security & Policy Enforcement
Mitigation: While exfiltration is not applicable, the attacker's ability to disrupt services through unauthorized frequency use would likely be constrained.
The overall impact of service disruption would likely be reduced, limiting the attacker's ability to interfere with critical communications.
Impact at a Glance
Affected Business Functions
- Public Safety Communications
- Utility Infrastructure Operations
- Fixed Satellite Services
Estimated downtime: N/A
Estimated loss: N/A
Potential interference with critical communication systems, leading to service degradation or outages.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust validation mechanisms for client-reported location data to prevent GPS spoofing.
- • Enhance authentication protocols within AFC systems to verify the integrity of client inputs.
- • Deploy anomaly detection systems to identify and mitigate unauthorized frequency assignments.
- • Establish continuous monitoring and logging of AFC communications to detect and respond to suspicious activities.
- • Collaborate with industry stakeholders to develop and enforce standards for secure AFC operations.



