peter bassill · operator
$ cve CVE-2024-20017 JSON

CVE-2024-20017

9.8
CRITICAL · CVSS 3.1 · EPSS 46.6% (pctl 99)

Patch early

EPSS 46.6% — above the 10% action threshold.

Description

In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS46.61% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploitnone known
Published2024-03-04
Last modified2026-06-17

Affected (8)

VendorProduct
mediatekmt6890
mediatekmt7622
mediatekmt7915
mediatekmt7916
mediatekmt7981
mediatekmt7986
mediateksoftware development kit
openwrtopenwrt

References

→ the Explorer  ·  watch your stack  ·  NVD