Vulnerability record · CVE-2024-20017 · published 4 March 2024
CVE-2024-20017: MediaTek wlan service out-of-bounds write allows remote code execution
Mediatek · Software Development Kit
The MediaTek wlan service fails to properly validate input, leading to an out-of-bounds write. This flaw can be triggered remotely without authentication or user interaction, enabling code execution on affected devices. It affects MediaTek software development kit and OpenWrt products.
Description
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation Patch ID: WCNCR00350938; Issue ID: MSV-1132.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS score is 9.8 (critical), remote code execution with no authentication or user interaction, and public exploits exist with high EPSS probability.
What it is
The MediaTek wlan service fails to properly validate input, leading to an out-of-bounds write. This flaw can be triggered remotely without authentication or user interaction, enabling code execution on affected devices. It affects MediaTek software development kit and OpenWrt products.
Impact
An unauthenticated remote attacker can execute arbitrary code with the privileges of the wlan service, potentially gaining full control of the device. This could lead to data theft, persistent compromise, or use in botnets.
Attack surface
The vulnerability is reachable over the network via the wlan service, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
Public exploit code and technical descriptions exist, and EPSS indicates a high probability of exploitation (0.46609, 98.8th percentile). The vulnerability is not listed in CISA KEV.
What to do
- Apply the vendor patch referenced by Patch ID WCNCR00350938 as soon as it is available for your device.
- Check MediaTek's March 2024 product security bulletin and OpenWrt advisories for updated firmware and apply them.
- If patching is not immediately possible, restrict network access to the wlan service and monitor for anomalous traffic.
- Segment affected devices on isolated network segments to limit lateral movement if compromised.
- Disable the wlan service if it is not required for operations.
Detection
- Monitor network traffic for unusual packets targeting the wlan service port or protocol.
- Inspect device logs for crashes or abnormal behavior in the wlan service process.
- Use intrusion detection systems with signatures for CVE-2024-20017 if available.
- Watch for unexpected outbound connections or process creation on affected devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://corp.mediatek.com/product-security-bulletin/March-2024 | Vendor Advisory |
| https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-2024-20017-four-different-ways.html | ExploitTechnical DescriptionThird Party Advisory |
| https://blog.sonicwall.com/en-us/2024/09/critical-exploit-in-mediatek-wi-fi-chipsets-zero-click-vulnerability-cve-2024-2 | ExploitThird Party Advisory |
| https://corp.mediatek.com/product-security-bulletin/March-2024 | Vendor Advisory |
| https://news.ycombinator.com/item?id=41605680 | Third Party Advisory |
Track CVE-2024-20017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-20017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.