CVE-2017-9417, known as "Broadpwn," is a critical vulnerability affecting Broadcom BCM43xx Wi-Fi chips, including specific BCM4354, BCM4358, and BCM4359 models, as well as their firmware. This flaw allows remote attackers to execute arbitrary code without authentication or user interaction. With a CVSS score of 9.8 (CRITICAL) and a FAUCET Risk Score of 98/100, the vulnerability poses a severe risk, enabling full compromise of affected devices. While not listed in CISA's KEV catalog, there is public exploit code available for a Denial of Service (DoS) and significant community discussion, indicating high awareness and potential for broader exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:broadcom:bcm43xx_wi-fi_chipset_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.