← Vulnerability feed

Vulnerability record · CVE-2017-9417 · published 4 June 2017

CVE-2017-9417: Broadcom BCM43xx Wi-Fi chipset firmware remote code execution (Broadpwn)

Broadcom · Bcm43xx Wi Fi Chipset Firmware

Broadcom BCM43xx Wi-Fi chipsets contain a flaw that lets remote attackers execute arbitrary code, known as Broadpwn. The NVD description provides no technical detail on the underlying defect, but the CVSS vector rates it network-reachable with no privileges or user interaction, making it a serious pre-authentication risk for affected devices.

9.8 CVSS 3.0 Critical EPSS 64% · top 0.8%
9.8CVSS 3.0 base score, v2 7.5
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
17 Jun 2026Last modified by NVD

Description

Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn" issue.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, and no user interaction, combined with a very high EPSS percentile, warrants critical priority despite the thin technical description.

What it is

Broadcom BCM43xx Wi-Fi chipsets contain a flaw that lets remote attackers execute arbitrary code, known as Broadpwn. The NVD description provides no technical detail on the underlying defect, but the CVSS vector rates it network-reachable with no privileges or user interaction, making it a serious pre-authentication risk for affected devices.

Impact

An attacker can execute arbitrary code on the Wi-Fi chipset, potentially gaining control of the device's wireless subsystem and pivoting to the host OS. Because the chipset handles over-the-air traffic, compromise can occur without any user action.

Attack surface

Reachable over the network via the Wi-Fi interface (AV:N, PR:N, UI:N), meaning an attacker within radio range can trigger it without credentials or user interaction. The record does not specify the exact packet or protocol path involved.

Exploitation

Not listed in CISA KEV and no reference is tagged as exploit code, but EPSS is 0.63997 (99.185th percentile), indicating a high modeled likelihood of exploitation activity. The record does not confirm public exploit availability.

What to do

  • Apply vendor firmware and OS updates for affected Broadcom BCM43xx devices (Android July 2017 bulletin, Apple HT210121, Microsoft advisory, Debian LTS).
  • Where patching is not possible, disable Wi-Fi or restrict the device to trusted networks to reduce exposure to over-the-air attacks.
  • Inventory devices using Broadcom BCM43xx chipsets and prioritize those that cannot be updated or replaced.
  • Monitor vendor advisories for updated firmware, since the chipset firmware may need separate updating from the host OS.

Detection

  • Monitor for anomalous Wi-Fi chipset behavior or crashes that could indicate exploitation attempts.
  • Track devices running unpatched firmware against the referenced vendor advisories.
  • Review network logs for unexpected wireless activity from affected devices, though the record provides no specific indicators of compromise.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9417 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2017-9417), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.