CVE-2021-37565: High severity mediatek mt7603e firmware vulnerability
Published Dec 25, 2021
·Updated
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).
Affected Software
14 affected components
MediaTek Mt7603e Firmware=2.0.2
MediaTek MT7603E
MediaTek Mt7613 Firmware=2.0.2
MediaTek MT7613
MediaTek Mt7615 Firmware=2.0.2
MediaTek MT7615
MediaTek Mt7622 Firmware=2.0.2
MediaTek MT7622
MediaTek Mt7628 Firmware=2.0.2
MediaTek MT7628
MediaTek Mt7629 Firmware=2.0.2
MediaTek MT7629
MediaTek Mt7915 Firmware=2.0.2
MediaTek MT7915
Event History
Dec 25, 2021
CVE Published
via MITRE·11:23 PM
Data Sourced
via MITRE·11:23 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2021-37565?
CVE-2021-37565 is a vulnerability that affects MediaTek microchips used in NETGEAR devices and other devices, leading to mishandling of IEEE 1905 protocols.
2
Which chipsets are affected by CVE-2021-37565?
The affected chipsets are MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, and MT7915.
3
What are the affected software versions of CVE-2021-37565?
The affected software version is 2.0.2.
4
What is the severity of CVE-2021-37565?
The severity of CVE-2021-37565 is high, with a severity value of 7.5.
5
How can I fix CVE-2021-37565?
To fix CVE-2021-37565, it is recommended to update the firmware to a version that addresses the vulnerability.