WPS Misconfiguration Vulnerability in NETGEAR Devices Using MediaTek Chipsets
CVE-2021-37563

8.2HIGH

Key Information:

Vendor
Mediatek
Vendor
CVE Published:
26 December 2021

Summary

MediaTek microchips used in NETGEAR devices have a vulnerability where the WPS (Wi-Fi Protected Setup) protocol is mishandled. This security flaw allows for potential out-of-bounds write conditions, which could lead to unauthorized access to the network. Devices utilizing affected chipsets, including several models across various NETGEAR offerings, are vulnerable if running specific software versions. Appropriate measures should be taken to patch the devices and mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.