CVE-2017-6956: Broadcom Hardmac Wi-Fi Soc Firmware

High severity, CVSS 8.8. EPSS: 2% chance of exploitation in the next 30 days.

On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition Information Element (FT-IE).

Affected products

  • Broadcom Hardmac Wi-Fi Soc Firmware: version 6.37.34.40 only

Published 2017-04-05. Last modified 2026-06-17.