WPS Protocol Vulnerability in NETGEAR Devices Using MediaTek Chipsets
CVE-2021-37560
8.2HIGH
Summary
MediaTek microchips present in various NETGEAR devices have a vulnerability related to the Wi-Fi Protected Setup (WPS) protocol. This flaw arises from mishandling WPS requests, leading to potential out-of-bounds writes, which could allow attackers to exploit the device's firmware. The affected chipsets include MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, and MT7915. Users are advised to check for updates and apply necessary patches to mitigate the risk.
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved