NULL pointer dereference in MediaTek products - CVE-2022-32663
Published: February 7, 2023
Vulnerability identifier: #VU71988
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-32663
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in Wi-Fi driver. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.
Affected software
MT7921
MT8788
MT8532
MT8385
MT8365
MT8362A
MT8175
MT8167S
MT7986
MT7981
MT5221
MT7916
MT7915
MT7902
MT7668
MT7629
MT7628
MT7622
MT7615
MT7613
MT7603
MT8518S
MT8788
MT8532
MT8385
MT8365
MT8362A
MT8175
MT8167S
MT7986
MT7981
MT5221
MT7916
MT7915
MT7902
MT7668
MT7629
MT7628
MT7622
MT7615
MT7613
MT7603
MT8518S
How to mitigate CVE-2022-32663
Install updates from vendor's website.