CVE-2021-37561

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mediatek:mt7603e_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mediatek:mt7612_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7612:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mediatek:mt7613_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mediatek:mt7615_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mediatek:mt7622_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mediatek:mt7628_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mediatek:mt7629_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mediatek:mt7915_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mediatek:mt7620_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7620:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mediatek:mt7610_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7610:-:*:*:*:*:*:*:*

History

10 Jan 2022, 18:28

Type Values Removed Values Added
References (MISC) https://kb.netgear.com/000064368/Security-Advisory-for-WiFi-WPS-and-IEEE-1905-Vulnerabilities-on-Multiple-Products-PSV-2021-0298-PSV-2021-0300 - (MISC) https://kb.netgear.com/000064368/Security-Advisory-for-WiFi-WPS-and-IEEE-1905-Vulnerabilities-on-Multiple-Products-PSV-2021-0298-PSV-2021-0300 - Third Party Advisory
References (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - Vendor Advisory
First Time Mediatek mt7612 Firmware
Mediatek mt7612
Mediatek mt7613 Firmware
Mediatek mt7613
Mediatek mt7629 Firmware
Mediatek mt7915
Mediatek mt7620 Firmware
Mediatek mt7915 Firmware
Mediatek mt7615
Mediatek mt7610
Mediatek mt7603e Firmware
Mediatek mt7622
Mediatek mt7615 Firmware
Mediatek mt7603e
Mediatek mt7622 Firmware
Mediatek mt7629
Mediatek mt7628
Mediatek
Mediatek mt7628 Firmware
Mediatek mt7620
Mediatek mt7610 Firmware
CPE cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7615_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7610_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7612_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7610:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7629_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7915_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7622_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7612:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7603e_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7613_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7628_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7620:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7620_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.3
v3 : 8.8
CWE CWE-787

05 Jan 2022, 22:15

Type Values Removed Values Added
References
  • (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 -
Summary MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).

26 Dec 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-26 00:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-37561

Mitre link : CVE-2021-37561

CVE.ORG link : CVE-2021-37561


JSON object : View

Products Affected

mediatek

  • mt7603e_firmware
  • mt7628
  • mt7620
  • mt7615
  • mt7610
  • mt7603e
  • mt7615_firmware
  • mt7915
  • mt7628_firmware
  • mt7622_firmware
  • mt7613
  • mt7610_firmware
  • mt7612_firmware
  • mt7629_firmware
  • mt7915_firmware
  • mt7629
  • mt7612
  • mt7622
  • mt7613_firmware
  • mt7620_firmware
CWE
CWE-787

Out-of-bounds Write