Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2024-20137 PoC — MediaTek Chipsets 安全漏洞

Source
Associated Vulnerability
Title: MediaTek Chipsets 安全漏洞 (CVE-2024-20137)
Description:In wlan driver, there is a possible client disconnection due to improper handling of exceptional conditions. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00384543; Issue ID: MSV-1727.
Description
Python code for expoiting of vulnerability in wlan driver of MediaTek SOCs MT6890, MT7622, MT7915, MT7916, MT7981, MT7986
Readme
# CVE-2024-20137
Python code for expoiting the vulnerability in wlan driver of MediaTek SOCs MT6890, MT7622, MT7915, MT7916, MT7981, MT7986

MediaTek: https://corp.mediatek.com/product-security-bulletin/December-2024

NIST: https://nvd.nist.gov/vuln/detail/CVE-2024-20137



# About the code
This code is written in Python 3 and uses the Scapy library to craft and send custom 802.11 authentication frames over a wireless interface. 
It simulates an authentication process involving the Simultaneous Authentication of Equals (SAE), which is part of WPA3's enhanced security mechanism.
It sends an authentication request via a protocol number that is not registered or is a vendor-specific and forces the client to deauthenticate.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →