Out of Bounds Write Vulnerability in Mediatek WLAN STA Firmware
CVE-2024-20148

9.8CRITICAL

Summary

A vulnerability in Mediatek's WLAN STA firmware allows for a possible out of bounds write due to improper input validation. This flaw enables remote code execution without requiring any user interaction or additional privileges. Implementing the latest patches (Patch ID: WCNCR00389045 / ALPS09136494) is essential to safeguard affected systems from exploitation. For more information, visit the Mediatek product security bulletin.

Affected Version(s)

MT3603, MT6835, MT6878, MT6886, MT6897, MT7902, MT7920, MT7922, MT8518S, MT8532, MT8766, MT8768, MT8775, MT8796, MT8798 Android 13.0, 14.0, 15.0 / SDK release 2.4 and before / Yocto 3.3, 4.0, 5.0

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.