CVE-2021-35055: Critical severity mediatek mt7603e firmware vulnerability
Published Dec 25, 2021
·Updated
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).
Affected Software
20 affected components
MediaTek Mt7603e Firmware=7.4.0.0
MediaTek MT7603E
MediaTek Mt7612 Firmware=7.4.0.0
MediaTek MT7612
MediaTek Mt7613 Firmware=7.4.0.0
MediaTek MT7613
MediaTek Mt7615 Firmware=7.4.0.0
MediaTek MT7615
MediaTek Mt7622 Firmware=7.4.0.0
MediaTek MT7622
MediaTek Mt7628 Firmware=7.4.0.0
MediaTek MT7628
MediaTek Mt7629 Firmware=7.4.0.0
MediaTek MT7629
MediaTek Mt7915 Firmware=7.4.0.0
MediaTek MT7915
MediaTek Mt7620 Firmware=7.4.0.0
MediaTek MT7620
MediaTek Mt7610 Firmware=7.4.0.0
MediaTek MT7610
Event History
Dec 25, 2021
CVE Published
via MITRE·11:26 PM
Data Sourced
via MITRE·11:26 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-35055.
2
Which devices are affected by this vulnerability?
This vulnerability affects MediaTek microchips as used in NETGEAR devices through 2021-11-11 and other devices.
3
What is the severity of CVE-2021-35055?
The severity of CVE-2021-35055 is critical with a CVSS score of 8.8.
4
How does this vulnerability impact the WPS protocol?
This vulnerability in MediaTek microchips mishandles the WPS (Wi-Fi Protected Setup) protocol.
5
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to refer to the security advisories and patches provided by MediaTek and NETGEAR.