PT-2021-5740 · Mediatek · Mediatek Microchips

Published

2021-11-23

·

Updated

2022-01-10

·

CVE-2021-37566

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MediaTek microchips versions 2.0.2 MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915
Description The issue is related to the mishandling of IEEE 1905 protocols, which can lead to an out-of-bounds write in memory. This can allow a remote attacker to elevate their privileges. The estimated number of potentially affected devices is not specified.
Recommendations For version 2.0.2, update to a newer version to mitigate the risk. For MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915, consider disabling the IEEE 1905 protocol handling until a patch is available. Restrict access to the vulnerable microchips to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00183
CVE-2021-37566

Affected Products

Mediatek Microchips