CVE-2019-18989: MediaTek MT7620N Firmware

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A partial authentication bypass vulnerability exists on Mediatek MT7620N 1.06 devices. The vulnerability allows sending an unencrypted data frame to a WPA2-protected WLAN router where the packet is routed through the network. If successful, a response is sent back as an encrypted frame, which would allow an attacker to discern information or potentially modify data.

Affected products

  • MediaTek MT7620N Firmware: version 1.06 only

Published 2020-09-30. Last modified 2026-06-17.