MaximAlert

Thought Leadership

6 GHz Wi-Fi Flaws Could Disrupt Critical Systems

Dark Reading

July 14, 2026

Visit Count : 9

The technology keeping 6 GHz Wi-Fi from interfering with critical infrastructure has a number of security issues — and researchers are starting to sound the alarm.

Researchers from Pennsylvania State University and Idaho National Laboratory will discuss their findings in a session called "Blind Trust in the 6 GHz Band: Weaponizing Wi-Fi Automated Frequency Coordination (AFC)" at Black Hat USA 2026. Two pieces of technology are at the center of this research: the cutting edge 6 GHz Wi-Fi spectrum and AFC, which regulates the 6 GHz band and keeps its powerful signal from interfering with radio towers, cellular backhaul, and spectrum-adjacent public safety networks.

The researchers behind the presentation, who've also published two related white papers this year, believe these AFC systems have significant security weaknesses that could potentially interfere with critical signals.

Client-Side Opportunities for AFC Interference

The core idea is that while communication between Wi-Fi access points (APs) and AFC servers is protected by transport layer security (TLS) that prevents eavesdropping and tampering, AFC servers by default trust data from the external client side, such as Global Positioning System (GPS), Global Navigation Satellite System (GNSS), Wi-Fi-based location data, DNS responses, and Network Time Protocol (NTP) time synchronization. An attacker can manipulate these inputs depending on the scenario, the researchers say.

While no attacks have been identified in the wild to date, the researchers argue that AFC architecture currently makes several assumptions that could be exploited by either malicious actors or unintentional misconfigurations.

"These out-of-band dependencies create practical off-path attack vectors, allowing an off-path adversary to spoof wireless signals, poison DNS responses, or manipulate NTP, causing an AP to report a false location/time, be redirected to attacker-controlled endpoints, or prematurely expire/force AFC leases," researchers wrote in one white paper covering the issue broadly. "Such attacks lead to incorrect frequency/power assignments (which can cause harmful interference to incumbents) and denial-of-service for 6-GHz clients when APs are prevented from receiving valid frequency allocations."

A user could fake GPS signals or Wi-Fi geolocation data to cause an AP to report a false location to the AFC server; this can be used to obtain unauthorized channel and power assignments. Additionally, by moving the AP to a less restricted location, the AFC server could authorize higher transmit power, which could interfere with protected service links and radio observatories.

An attacker could also trigger a denial-of-service attack by spoofing locations outside supported regions, manipulating time synchronization (via the NTP), poisoning DNS lookups, and preventing APs from receiving valid AFC authorizations, potentially disabling 6 GHz operation altogether. Similarly, an attacker could force repeated AFC signal connection updates and trigger unnecessary re-queries and increased server load.

second white paper released last month detailed what the researchers described as the first practical proof-of-concept attack against commercial Wi-Fi APs by impersonating an AFC server, injecting forged responses, and launching targeted interference and DoS attacks within protected frequencies. While separate from the issues identified in the earlier research, the latter paper demonstrates that implementation flaws in some AFC clients can also allow attackers to manipulate AFC decisions.

This research was funded by the Department of Energy (DOE), including the Office of Cybersecurity, Energy Security, and Emergency Response (CESER), and it was conducted in collaboration with the Idaho National Laboratory (INL).

The Road Ahead to Address AFC Issues

Yilu Dong, a doctoral candidate at Penn State University and a researcher behind the report, tells Dark Reading that even though none of these examples are exactly system-level malicious attacks, the risk is real.

In fact, malicious intentions aren't even necessary for these issues to rear their head. A consumer might attempt to expand the coverage of their own AP and bypass the AFC, yet inadvertently cause the interference laid out in the research.

"Even consumer-level 6-GHz devices can still cause interference that leads to degradation in the channel and in some very severe cases it can even put a channel into an unusable state," he says. "I think this just shows that interference is not something that's theoretical, but can actually impact all of our critical systems."

There are a number of ways the research team recommends stakeholders address the issues with AFC systems, though the broader white paper acknowledges that addressing these issues is a non-trivial process because deployment costs directly conflict with stakeholder cost-efficiency goals.

Proposed solutions include geofencing, using multiple location sources, physical-level spoofing detection, coordinated detection, authenticated localization messages, implementing secure DNS and NTP protocols, and updating dependencies. The researchers suggest prioritizing location spoofing detection and disabling 6 GHz operations when anomalies are detected.

Dong and his fellow researcher, Tianchang Yang — also of Penn State — tell Dark Reading that, right now, their priority is getting the word out to vendors that make and interact with AFC systems in the hopes that stakeholders will take action to secure these critical systems.

While some vendors the team spoke with received the research positively and will consider changes, other vendors have been more mixed. Yang explains there's a feeling among some stakeholders that the issue isn't major or that there's a preference toward usability.

"I don't think they will drop the AFC system, or they will make major changes to the AFC system in a short period of time," he says. "But they are aware of these issues, and we are working together to discuss some potential solutions."

contact