Trusting the Untrusted: How 6 GHz Wi-Fi's Traffic Cop Could Be Turned Against Critical Infrastructure- 264
July 16, 2026
The system designed to keep the 6 GHz Wi-Fi band from interfering with radio towers, cellular backhaul, and public-safety networks rests on an assumption researchers say no longer holds (...) creating an attack surface that sits entirely outside the encrypted channel securing communication between access points and AFC servers.
The system designed to keep the 6 GHz Wi-Fi band from interfering with radio towers, cellular backhaul, and public-safety networks rests on an assumption researchers say no longer holds: that the data an access point reports about its own location and timing can be trusted at face value. Findings set for presentation at Black Hat USA 2026 by researchers from Pennsylvania State University and Idaho National Laboratory, developed with Department of Energy funding, describe how Automated Frequency Coordination systems — the technical arbiters that allocate 6 GHz spectrum to keep it clear of protected signals — accept unverified client-side inputs including GPS, DNS responses, and network time synchronization, creating an attack surface that sits entirely outside the encrypted channel securing communication between access points and AFC servers.

The mechanics matter because AFC decisions are safety-critical rather than merely operational. An attacker able to spoof GPS or Wi-Fi-based location data can cause an access point to misreport its position and receive channel and power authorizations intended for a different, less-restricted area — potentially interfering with protected service links or radio astronomy observatories. The same class of manipulation, applied to time synchronization or DNS resolution, can prevent an access point from renewing its frequency lease at all, producing a denial-of-service condition that silently disables 6 GHz operation. A second research paper, released the prior month, moved beyond theoretical exposure to demonstrate a working proof-of-concept: impersonating an AFC server itself and injecting forged responses to trigger targeted interference against commercial access points.
What distinguishes this research from a conventional vulnerability disclosure is the researchers' emphasis that malicious intent isn't even a precondition for harm — a consumer attempting to legitimately extend their own network's coverage could trigger the same interference inadvertently, meaning the risk profile spans well beyond deliberate attackers to encompass ordinary misconfiguration at scale. The researchers' proposed mitigations — geofencing, multiple independent location sources, authenticated localization messages, and secure DNS/NTP implementations — face an adoption headwind common to critical-infrastructure security generally: deployment cost sits in direct tension with the usability and cost-efficiency priorities of the vendors who would need to implement them, leaving the timeline for remediation, by the researchers' own account, an open and unresolved question.