VYPR
Unrated severityNVD Advisory· Published Dec 25, 2021· Updated Aug 3, 2024

CVE-2021-32469

CVE-2021-32469

Description

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915 Affected Software Versions 7.4.0.0; Out-of-bounds read).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read vulnerability in MediaTek WPS implementation on NETGEAR and other devices allows potential information disclosure.

Vulnerability

CVE-2021-32469 is an out-of-bounds read vulnerability in the Wi-Fi Protected Setup (WPS) protocol handling of MediaTek microchips. The affected chipsets include MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, and MT7915, running software version 7.4.0.0. The bug occurs when the device processes WPS messages, leading to a read beyond the allocated buffer. This vulnerability affects NETGEAR devices and other products using these chipsets [1][2].

Exploitation

An attacker within Wi-Fi range can exploit this vulnerability by sending a specially crafted WPS frame to the target device. No authentication or user interaction is required; the attacker only needs to be able to initiate a WPS exchange. The out-of-bounds read is triggered during the parsing of the malicious WPS message [1][2].

Impact

Successful exploitation results in an out-of-bounds read, which may disclose sensitive memory contents from the device. This could lead to information disclosure of Wi-Fi credentials or other data. The vulnerability is rated as Medium severity by MediaTek [1].

Mitigation

NETGEAR has released firmware updates for many affected products, including extenders (e.g., EAX11v2, EX3700, EX6120) and access points (e.g., WAC104, WAX202) [2]. MediaTek notified OEMs and provided patches in the January 2022 bulletin [1]. No workarounds are available; users should apply the latest firmware from their device vendor. Devices that are no longer supported may remain vulnerable [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.