Two sentences: SonicWall researchers warn of CVE-2024-20017, a critical zero-click vulnerability in MediaTek Wi-Fi chipsets that enables remote code execution without user interaction. Patches are available and users should update firmware immediately; exploitation risk rises as a public PoC becomes accessible. #CVE-2024-20017 #MediaTek #MT7622 #MT7915 #OpenWrt #Ubiquiti #Xiaomi #Netgear
Keypoints
- Vulnerability ID: CVE-2024-20017
- CVSS Score: 9.8 (Critical)
- Affected Devices: MediaTek Wi-Fi chipsets MT7622/MT7915 and RTxxxx SoftAP driver bundles
- Impact: Remote code execution without user interaction
- Exploitation Method: Buffer overflow via attacker-controlled packet data
- Mitigation: MediaTek has released patches; users should update immediately
- Public PoC Availability: Recently made available, increasing exploitation risk
- SonicWall Protections: IPS signatures released for detection
MITRE Techniques
- [T1203] Exploitation for Client Execution β The vulnerability is exploited to execute arbitrary code via attacker-controlled packet length. Quote: βThe vulnerability is a buffer overflow as a result of a length value taken directly from attacker-controlled packet data without bounds checking and placed into a memory copy.β
- [T1059] Command and Scripting Interpreter β Exploitation uses command-line interfaces to maintain access. Quote: βThis method leverages the `system()` call to execute commands, such as sending a reverse shell back to the attacker.β
- [T1068] Privilege Escalation β Exploiting vulnerabilities to gain higher privileges. Quote: βExploiting vulnerabilities to gain higher privileges.β
- [T1218] Defense Evasion β Using legitimate tools to bypass defenses. Quote: βUsing legitimate tools to bypass defenses.β
- [T1071] Command and Control β Using application layer protocols for command and control. Quote: βUsing application layer protocols for command and control.β
Indicators of Compromise
- [Domain] Context β corp.mediatek.com, github.com
- [CVE] Vulnerability IDs β CVE-2024-20017
- [IPS Signature] Detection signatures β 20322, 20323