Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 7 |
CVE-ID | CVE-2025-20046 CVE-2025-20032 CVE-2025-20618 CVE-2025-20006 CVE-2025-20039 CVE-2025-20026 CVE-2025-20062 |
CWE-ID | CWE-416 CWE-20 CWE-121 CWE-362 CWE-125 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
Intel Wi-Fi 6 AX200 Hardware solutions / Firmware Intel Wi-Fi 6E AX210 Hardware solutions / Firmware Intel Wi-Fi 6E AX211 Hardware solutions / Firmware Intel Wi-Fi 6 AX201 Hardware solutions / Firmware Intel Wi-Fi 7 BE200 Hardware solutions / Firmware Intel Wi-Fi 7 BE201 Hardware solutions / Firmware Intel Wi-Fi 7 BE202 Hardware solutions / Firmware Intel Wi-Fi 6 AX101 Hardware solutions / Firmware Intel Wi-Fi 6 AX203 Hardware solutions / Firmware |
Vendor | Intel |
Security Bulletin
This security bulletin contains information about 7 vulnerabilities.
EUVDB-ID: #VU109176
Risk: Medium
CVSSv4.0: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-20046
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error. A remote attacker on the local network can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 6 AX200: before 23.100
Intel Wi-Fi 6E AX210: before 23.100
Intel Wi-Fi 6E AX211: before 23.100
Intel Wi-Fi 6 AX201: before 23.100
Intel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
Intel Wi-Fi 6 AX101: before 23.100
Intel Wi-Fi 6 AX203: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109179
Risk: Low
CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-20032
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local administrator can pass specially crafted input to the application and perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 6 AX201: before 23.100
Intel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
Intel Wi-Fi 6 AX101: before 23.100
Intel Wi-Fi 6 AX203: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109180
Risk: Low
CVSSv4.0: 4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2025-20618
CWE-ID:
CWE-121 - Stack-based buffer overflow
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error. A local administrator can trigger stack-based buffer overflow and cause a denial of service condition on the target system.
MitigationInstall update from vendor's website.
Vulnerable software versionsIntel Wi-Fi 6 AX200: before 23.100
Intel Wi-Fi 6E AX210: before 23.100
Intel Wi-Fi 6E AX211: before 23.100
Intel Wi-Fi 6 AX201: before 23.100
Intel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
Intel Wi-Fi 6 AX101: before 23.100
Intel Wi-Fi 6 AX203: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109183
Risk: Medium
CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-20006
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error. A remote attacker on the local network can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109184
Risk: Medium
CVSSv4.0: 2.1 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-20039
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a race condition. A remote attacker on the local network can exploit the race and cause a denial of service condition on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109185
Risk: Medium
CVSSv4.0: 2.3 [CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-20026
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition. A remote attacker on the local network can trigger an out-of-bounds read error and cause a denial of service condition on the system.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU109186
Risk: Medium
CVSSv4.0: 2.3 [CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2025-20062
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error. A remote attacker on the local network can perform a denial of service (DoS) attack.
MitigationInstall updates from vendor's website.
Vulnerable software versionsIntel Wi-Fi 6E AX211: before 23.100
Intel Wi-Fi 6 AX201: before 23.100
Intel Wi-Fi 7 BE200: before 23.100
Intel Wi-Fi 7 BE201: before 23.100
Intel Wi-Fi 7 BE202: before 23.100
Intel Wi-Fi 6 AX101: before 23.100
Intel Wi-Fi 6 AX203: before 23.100
CPE2.3https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01270.html
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.