Zero-Click MediaTek Bug Opens Phones, Wi-Fi to Takeover
ID: e216ea6a-5f56-5dc9-831a-e0630b25670f
STIX ID: report--e216ea6a-5f56-5dc9-831a-e0630b25670f
Feed Name: Dark Reading
Threat Score
A nearly max-critical zero-click vulnerability (CVE-2024-20017, CVSS 9.8) in MediaTek's wappd network daemon can lead to remote code execution on affected routers and smartphones (MediaTek SDK ≤7.4.0.1 and OpenWrt 19.07/21.02). Researchers disclosed the out-of-bounds write/buffer overflow and warned that a public proof-of-concept exploit is available; users and vendors are urged to apply MediaTek's patches immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
