Remote frame injection PoC by exploiting an A-MPDU vulnerability in 802.11n
github.com
github.com
This reminds me of the classic "+++ATH0" attack, where sending that string in for instance an IRC message caused some modems to hang up.
One solution is to scramble the data, so parts of it cannot be misinterpreted as lower-level framing, even if a few bits are corrupted. One good way to scramble the data is encryption, so even a trivially encrypted network (for instance, the password being the same as the SSID) would be immune to this attack.
Since the scrambling must be reversible, it would still be possible to generate the framing sequence with a different stream of data. It also only reduces the chances of the framing sequence appearing, but doesn't eliminate it completely.
The real solution is to ensure that the framing sequence is impossible to produce with normal data, by making it out-of-band with e.g. a different frequency or modulation.