> The affected versions include MediaTek SDK versions 7.4.0.1 and earlier, as well as OpenWrt 19.07 and 21.02. > The vulnerability resides in wappd, a network daemon included in the MediaTek MT7622/MT7915 SDK and RTxxxx SoftAP driver bundle. OpenWRT doesn't seem to use wappd though?
Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
61–70 of 109 posts
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#62Earlier quoted context omitted.
The consumer space is brutally competitive - you're working on tight margins and designs become obsolete very quickly. MediaTek's business is built on selling chips with the latest features at the lowest possible price. Everything has to be done at a breakneck pace that is dictated by the silicon. You start writing firmware as soon as the hardware design is finalised; it needs to be ready as soon as the chips are rea…
Intel networking used to have the expensive and works traits. Not confident their current products would be as good.
Inertia is a hell of a thing, but you are starting to see the cracks form. I just don’t know if there is an alternative.
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#63I've been buying laptops with AMD CPU's but they always come with these trash MediaTek RZ616 Wi-Fi cards, why is that? I've been replacing them with Intel Wi-Fi cards, now I have a pile of RZ616 cards ready to become future microplastics :-(
AMD decided to brand Mediatek's MT7921 and MT7922 as RZ608 and RZ616 to have something to sell to OEMs at the same price point as Intel's xx1 chips.
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#64The wording of the headline is a bit misleading here. I followed the link thinking it might be a firmware or silicon bug as I have a couple of routers at home with mt76 wifi, but was relieved to find it's just a bug in the vendor's 'sdk' shovelware. I'm baffled that anyone even thought about using that, given there's such good mt76 support from mainline kernels with hostapd.
Vendors plural to worry about:
“…driver bundles used in products from various manufacturers, including [but not limited to] Ubiquiti, Xiaomi and Netgear.”
That said, vendors (plural) say no products use this, e.g. Ubiquiti:
https://community.ui.com/questions/CVE-2024-20017/b3f1a425-d...
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#65> The affected versions include MediaTek SDK versions 7.4.0.1 and earlier, as well as OpenWrt 19.07 and 21.02. > The vulnerability resides in wappd, a network daemon included in the MediaTek MT7622/MT7915 SDK and RTxxxx SoftAP driver bundle. OpenWRT doesn't seem to use wappd though?
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#66Earlier quoted context omitted.
The consumer space is brutally competitive - you're working on tight margins and designs become obsolete very quickly. MediaTek's business is built on selling chips with the latest features at the lowest possible price. Everything has to be done at a breakneck pace that is dictated by the silicon. You start writing firmware as soon as the hardware design is finalised; it needs to be ready as soon as the chips are rea…
Intel networking used to have the expensive and works traits. Not confident their current products would be as good.
I'm talking things like full OS crashes while doing absolutely nothing, no traffic whatsoever or even better, silently starting to drop all network traffic (relatively silently, just an error message in the logs, but otherwise no indication, the interface still shows up as fine and up in the OS). It was all a driver issue (although both Intel drivers didn't work, so not only) that was later fixed.
After that, it was rock solid. But the fact that there was a high class network card sold for lots of money, on hardware compatibility lists at various vendors, which didn't work at all for pretty much everyone for more than a few years is disgusting.
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#67i still cannot fathom why in this day and age where people buy any silicon that's available, these C tier vendors don't adopt the PC strategy and completely open their firmwares for open source community.
FCC regulations around not making it easy to transmit outside of the licensed band tend to cause this.
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#68Earlier quoted context omitted.
FCC regulations around not making it easy to transmit outside of the licensed band tend to cause this.
Making the code available doesn’t necessarily mean that you can actually flash the image since it can be cryptographically locked down. Or even you support flashing but only let you do certain trusted operations from a signed image.
going the pc route is fully embracing your hardware accept whatever software the user wants. not throw unbuildable source somewhere and make it impossible to use. that's the faux open source we have today when someone must comply with the gpl or something
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#69Earlier quoted context omitted.
Why is it so much of this hardware/firmware feels so much like deploying a PoC to production? Why can't they hire someone that actually knows what they are doing?
The consumer space is brutally competitive - you're working on tight margins and designs become obsolete very quickly. MediaTek's business is built on selling chips with the latest features at the lowest possible price. Everything has to be done at a breakneck pace that is dictated by the silicon. You start writing firmware as soon as the hardware design is finalised; it needs to be ready as soon as the chips are rea…
Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
#70[flagged]
Can we stop with the snide comments now please? They're not helpful.