Vulnerabilities > Mediatek

DATE CVE VULNERABILITY TITLE RISK
2021-12-26 CVE-2021-37572 Missing Authorization vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.
network
low complexity
mediatek CWE-862
7.5
2021-12-26 CVE-2021-37583 Out-of-bounds Write vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols.
network
low complexity
mediatek CWE-787
8.8
2021-12-26 CVE-2021-37584 Out-of-bounds Write vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol.
network
low complexity
mediatek CWE-787
8.8
2021-12-26 CVE-2021-41788 Improper Input Validation vulnerability in Mediatek products
MediaTek microchips, as used in NETGEAR devices through 2021-12-13 and other devices, mishandle attempts at Wi-Fi authentication flooding.
network
low complexity
mediatek CWE-20
7.5
2021-09-09 CVE-2021-32484 Out-of-bounds Write vulnerability in Mediatek Modem Lr12A/Lr13
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow.
network
low complexity
mediatek CWE-787
7.5
2021-09-09 CVE-2021-32485 Out-of-bounds Write vulnerability in Mediatek Modem Lr12A/Lr13
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow.
network
low complexity
mediatek CWE-787
7.5
2021-09-09 CVE-2021-32486 Out-of-bounds Write vulnerability in Mediatek Modem Lr12A/Lr13
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow.
network
low complexity
mediatek CWE-787
7.5
2021-09-09 CVE-2021-32487 Out-of-bounds Write vulnerability in Mediatek Modem Lr12A/Lr13
In modem 2G RRM, there is a possible system crash due to a heap buffer overflow.
network
low complexity
mediatek CWE-787
7.5
2020-09-30 CVE-2019-18989 Authentication Bypass by Spoofing vulnerability in Mediatek Mt7620N Firmware 1.06
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices.
low complexity
mediatek CWE-290
5.4
2019-08-14 CVE-2019-15027 OS Command Injection vulnerability in Mediatek Mt6577 Firmware, Mt6625 Firmware and Mt8163 Firmware
The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, because clear_emmc_nomedia_entry in platform/mt6577/external/meta/emmc/meta_clr_emmc.c invokes 'system("/system/bin/rm -r /data/' followed by this filename upon an eMMC clearance from a Meta Mode boot.
network
low complexity
mediatek CWE-78
critical
9.8