CVE-2021-37565
Description
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bounds read).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read vulnerability in MediaTek chipsets mishandling IEEE 1905 protocols allows potential information disclosure; affects NETGEAR devices and others.
Vulnerability
CVE-2021-37565 is an out-of-bounds read vulnerability in MediaTek chipsets (MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915) when processing IEEE 1905 protocol packets. The flaw exists in software version 2.0.2 and affects devices using these chipsets, including multiple NETGEAR products [1][2]. The vulnerability is triggered by mishandling of IEEE 1905 frames, leading to reading beyond allocated memory boundaries.
Exploitation
An attacker on the local network can send specially crafted IEEE 1905 packets to a vulnerable device. No authentication or user interaction is required. The out-of-bounds read occurs during packet parsing, potentially allowing the attacker to access sensitive data from adjacent memory regions.
Impact
Successful exploitation could lead to information disclosure, as the out-of-bounds read may expose memory contents. The CVSS v3.1 base score is medium (exact score not specified in references). The attacker gains no direct code execution but may obtain sensitive information from the device's memory.
Mitigation
MediaTek has released patches, and NETGEAR has provided firmware updates for affected products within security support period. Fixed firmware versions include: EAX11v2 1.0.3.34, EAX12 1.0.3.34, EX3700 1.0.0.96, EX3800 1.0.0.96, EX6120 1.0.0.68, EX6130 1.0.0.48, EX6250v2 1.0.3.32, EX6400v3 1.0.3.32, EX6410v2 1.0.3.32, EX6470 1.0.3.32, WAC104 1.0.4.20, WAC124 1.0.4.8, WAX202 1.0.5.1, WAX206 1.0.4.0 [2]. No workarounds are available. Users should update to the latest firmware.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- MediaTek/microchipsdescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.