WPS Protocol Vulnerability in NETGEAR Devices Using MediaTek Microchips
CVE-2021-32468
8.2HIGH
Summary
NETGEAR devices equipped with MediaTek chipset models may mismanage the Wi-Fi Protected Setup (WPS) protocol, potentially leading to unauthorized access and compromised network security. The affected chipsets include MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, and MT7915, all of which were in use as of November 11, 2021. The flaw stems from an out-of-bounds read issue, which could allow attackers to exploit devices running version 7.4.0.0 software, emphasizing the need for network security measures and timely updates to safeguard against this vulnerability.
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved