CVE-2017-0561 is a critical remote code execution vulnerability affecting Broadcom Wi-Fi firmware in Android devices running Linux Kernel versions 3.10 and 3.18. This flaw, identified as a heap overflow (CWE-787), allows a remote attacker to execute arbitrary code within the Wi-Fi System on Chip (SoC) without user interaction. With a CVSS v3 score of 9.8 (Critical), the vulnerability presents a high risk due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While not currently listed in CISA's KEV catalog, public exploit code exists on ExploitDB, and it has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.10:*:*:*:*:*:*:* | ||
3.18CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.