Description
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds read).
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://kb.netgear.com/000064368/Security-Advisory-for-WiFi-WPS-and-IEEE-1905-Vulnerabilities-on-Multiple-Products-PSV-2021-0298-PSV-2021-0300
Vendor Advisory x_refsource_confirm
https://corp.mediatek.com/product-security-bulletin/January-2022
Scores
CVSS v3
8.2
EPSS
0.0061
EPSS Percentile
69.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-125
Status
published
Products (10)
mediatek/mt7603e_firmware
7.4.0.0
mediatek/mt7610_firmware
7.4.0.0
mediatek/mt7612_firmware
7.4.0.0
mediatek/mt7613_firmware
7.4.0.0
mediatek/mt7615_firmware
7.4.0.0
mediatek/mt7620_firmware
7.4.0.0
mediatek/mt7622_firmware
7.4.0.0
mediatek/mt7628_firmware
7.4.0.0
mediatek/mt7629_firmware
7.4.0.0
mediatek/mt7915_firmware
7.4.0.0
Published
Dec 26, 2021
Tracked Since
Feb 18, 2026