VYPR
Unrated severityNVD Advisory· Published Dec 25, 2021· Updated Aug 4, 2024

CVE-2021-37572

CVE-2021-37572

Description

MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Missing authorization).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

MediaTek Wi-Fi chipsets mishandle IEEE 1905 protocol packets, allowing unauthenticated network-based attacks that can lead to denial of service or potential code execution.

Vulnerability

CVE-2021-37572 is a missing authorization vulnerability in MediaTek Wi-Fi chipsets (MT7603E, MT7613, MT7615, MT7622, MT7628, MT7629, MT7915) running software version 2.0.2. The issue lies in the handling of IEEE 1905 protocol packets; affected devices do not properly authenticate or authorize incoming management frames, allowing the attacker to trigger the vulnerable code path without valid credentials [1][2].

Exploitation

An attacker does not need authentication or physical access. Exploitation requires only network proximity to the target device (within Wi-Fi range). By sending a malformed or specially crafted IEEE 1905 packet, the attacker can trigger the vulnerability. No user interaction is required [1][2].

Impact

Successful exploitation can lead to denial of service (device crash or reboot) and potentially arbitrary code execution on the affected chipset. The attacker gains the ability to disrupt network services or compromise the device's operation; the exact privilege level depends on the chipset context but can result in full control of the Wi-Fi subsystem [1][2].

Mitigation

MediaTek has released patches included in the January 2022 Product Security Bulletin [1]. NETGEAR has published firmware updates for many of its affected products (e.g., EAX11v2, EX3700, WAC104, WAX202) as listed in their advisory [2]. Users should update to the latest firmware versions provided by their device vendor. If a fixed version is not yet available for a specific product, no workaround exists [2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.