CVE-2019-18989
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
30/09/2020
Last modified:
21/07/2021
Description
A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
4.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mediatek:mt7620n_firmware:1.06:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt7620n:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



