CVE-2021-41788

MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mediatek:mt7603e_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mediatek:mt7612_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7612:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mediatek:mt7613_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mediatek:mt7615_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mediatek:mt7622_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mediatek:mt7628_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mediatek:mt7629_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mediatek:mt7915_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*

History

06 Jan 2022, 15:41

Type Values Removed Values Added
First Time Mediatek mt7612 Firmware
Mediatek mt7612
Mediatek mt7613
Mediatek mt7629 Firmware
Mediatek mt7915
Mediatek mt7628 Firmware
Mediatek mt7615
Mediatek mt7603e Firmware
Mediatek mt7622
Mediatek mt7615 Firmware
Mediatek mt7603e
Mediatek mt7622 Firmware
Mediatek mt7628
Mediatek
Mediatek mt7613 Firmware
Mediatek mt7629
Mediatek mt7915 Firmware
CVSS v2 : unknown
v3 : unknown
v2 : 7.8
v3 : 7.5
CWE CWE-20
CPE cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7615_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7612_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7628:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7629:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7629_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7915_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7622_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7622:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7612:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7613:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7603e_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7613_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7628_firmware:7.4.0.0:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7603e:-:*:*:*:*:*:*:*
References (MISC) https://kb.netgear.com/000064369/Security-Advisory-for-WiFi-Authentication-Flooding-Vulnerabilities-on-Multiple-Products-PSV-2021-0299-PSV-2021-0301 - (MISC) https://kb.netgear.com/000064369/Security-Advisory-for-WiFi-Authentication-Flooding-Vulnerabilities-on-Multiple-Products-PSV-2021-0299-PSV-2021-0301 - Third Party Advisory
References (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 - Vendor Advisory

05 Jan 2022, 22:15

Type Values Removed Values Added
References
  • (CONFIRM) https://corp.mediatek.com/product-security-bulletin/January-2022 -
Summary MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding. (Affected Chipsets MT7603E, MT7612, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0).

26 Dec 2021, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-26 00:15

Updated : 2023-12-10 14:09


NVD link : CVE-2021-41788

Mitre link : CVE-2021-41788

CVE.ORG link : CVE-2021-41788


JSON object : View

Products Affected

mediatek

  • mt7628_firmware
  • mt7622_firmware
  • mt7628
  • mt7613
  • mt7615
  • mt7603e_firmware
  • mt7612_firmware
  • mt7612
  • mt7603e
  • mt7622
  • mt7629_firmware
  • mt7915_firmware
  • mt7629
  • mt7615_firmware
  • mt7613_firmware
  • mt7915
CWE
CWE-20

Improper Input Validation