Mediatek Wi-Fi CVE-2024-20017

Since (at least newer releases) of vanilla OpenWrt do not use Mediatek’s wappd, current Turris OS is fine as well, I assume?

1 Like

Hello,

from what I can understand, the vulnerability is in any Mediatek wifi driver compiled using specific versions of Mediatek SDK (version 7.4.0.1 and before for MT7915). If Turris developers has used last versions of OpenWrt open source driver to build the firmware, we are safe. If they’ve used the Mediatek driver with SDK version 7.4.0.1 or before, we are not safe. Is there any developer who can confirm Turris routers don’t use Mediatek proprietary wifi drivers ?

source (CVE-2024-20017) https://corp.mediatek.com/product-security-bulletin/March-2024

Thank you in advance

1 Like

Hi @t0t3m and @DDD,

confirming, that we are using same package as OpenWrt upstream.

Best regards,

Tom

2 Likes

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.