← Back to browse · API

CVE-2024-20017

Severity
CRITICAL
CVSS
9.8
EPSS
0.46331
Risk score
55.42
CISA KEV
No
PoC
No
Published
2024-03-04
Modified
2024-09-25
First seen
2026-08-07
Aliases
EUVD-2024-17732, GHSA-QR26-2MPM-7J4X
Products
MediaTek, Inc.:MT6890, MT7915, MT7916, MT7981, MT7986 SDK version 7.4.0.1 and before (for MT7915) / SDK version 7.6.7.0 and before (for MT7916, MT7981 and MT7986) / OpenWrt 19.07, 21.02
Sources
euvd EUVD-2024-17732

Description

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

References