CVE-2021-41788
MEDIUMMediaTek MT7603E/MT7612/MT7613/MT7615/MT7622/MT7628/MT7629/MT7915 Firmware 7.4.0.0 Wi-Fi Auth Flood via Input Validation
Title source: llmDescription
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).
References (2)
Core 2
Core References
Third Party Advisory x_refsource_misc
https://kb.netgear.com/000064369/Security-Advisory-for-WiFi-Authentication-Flooding-Vulnerabilities-on-Multiple-Products-PSV-2021-0299-PSV-2021-0301
Vendor Advisory x_refsource_confirm
https://corp.mediatek.com/product-security-bulletin/January-2022
Scores
CVSS v3
6.5
EPSS
0.0055
EPSS Percentile
68.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L
Details
CWE
CWE-20
Status
published
Products (8)
mediatek/mt7603e_firmware
7.4.0.0
mediatek/mt7612_firmware
7.4.0.0
mediatek/mt7613_firmware
7.4.0.0
mediatek/mt7615_firmware
7.4.0.0
mediatek/mt7622_firmware
7.4.0.0
mediatek/mt7628_firmware
7.4.0.0
mediatek/mt7629_firmware
7.4.0.0
mediatek/mt7915_firmware
7.4.0.0
Published
Dec 26, 2021
Tracked Since
Feb 18, 2026