CVE-2021-37561

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 7.4.0.0; Out-of-bounds write).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
mitreCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AC:L/AV:N/A:L/C:H/I:N/PR:N/S:U/UI:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 66%
VendorProductVersion
mediatekmt7603e_firmware
7.4.0.0
mediatekmt7612_firmware
7.4.0.0
mediatekmt7613_firmware
7.4.0.0
mediatekmt7615_firmware
7.4.0.0
mediatekmt7622_firmware
7.4.0.0
mediatekmt7628_firmware
7.4.0.0
mediatekmt7629_firmware
7.4.0.0
mediatekmt7915_firmware
7.4.0.0
mediatekmt7620_firmware
7.4.0.0
mediatekmt7610_firmware
7.4.0.0
𝑥
= Vulnerable software versions