The auth check at nhrp_packet.c:817-819 skips authentication for Error Indication packets with error.code = AUTHENTICATION_FAILURE. An unauthenticated attacker can forge Error Indications that:
- Bypass auth completely (no token needed)
- Cancel pending NHRP requests (matching by predictable request_id)
- Inject NEGATIVE cache entries (block legitimate resolution for 3 min)
- Prevent spoke registration with the hub
Auth bypass condition (line 817-819): if (auth_token && (type != ERROR_INDICATION || code != AUTH_FAILURE)) → ERROR_INDICATION + AUTH_FAILURE → condition is FALSE → auth SKIPPED