logo

Zero-Click MediaTek Bug Opens Phones, Wi-Fi to Takeover

ID: e216ea6a-5f56-5dc9-831a-e0630b25670f

STIX ID: report--e216ea6a-5f56-5dc9-831a-e0630b25670f

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-09-20

Date Updated: 2026-04-21

Author: Dark Reading Staff

...
...

A nearly max-critical zero-click vulnerability (CVE-2024-20017, CVSS 9.8) in MediaTek's wappd network daemon can lead to remote code execution on affected routers and smartphones (MediaTek SDK ≤7.4.0.1 and OpenWrt 19.07/21.02). Researchers disclosed the out-of-bounds write/buffer overflow and warned that a public proof-of-concept exploit is available; users and vendors are urged to apply MediaTek's patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.