CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
9.0%
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.
Vendor | Product | Version | CPE |
---|---|---|---|
mediatek | nbiot_sdk | * | cpe:2.3:a:mediatek:nbiot_sdk:*:*:*:*:*:*:*:* |
mediatek | mt6890_firmware | * | cpe:2.3:a:mediatek:mt6890_firmware:*:*:*:*:*:*:*:* |
mediatek | mt7915_firmware | * | cpe:2.3:o:mediatek:mt7915_firmware:*:*:*:*:*:*:*:* |
mediatek | mt7916_firmware | * | cpe:2.3:o:mediatek:mt7916_firmware:*:*:*:*:*:*:*:* |
mediatek | mt7981_firmware | * | cpe:2.3:o:mediatek:mt7981_firmware:*:*:*:*:*:*:*:* |
mediatek | mt7986_firmware | * | cpe:2.3:o:mediatek:mt7986_firmware:*:*:*:*:*:*:*:* |
[
{
"vendor": "MediaTek, Inc.",
"product": "MT6890, MT7915, MT7916, MT7981, MT7986",
"versions": [
{
"version": "SDK version 7.4.0.1 and before (for MT7915) / SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986) / OpenWrt 19.07, 21.02",
"status": "affected"
}
]
}
]
More