CVE-2018-9394 is an out-of-bounds write vulnerability in the MediaTek Wi-Fi driver (mtk_p2p_wext_set_key) affecting Google Android devices. This flaw, rated Medium (CVSS 6.7), allows for local escalation of privilege to System execution with high impact on confidentiality, integrity, and availability, requiring high privileges but no user interaction for exploitation. While the vulnerability is not listed in CISA's KEV catalog and has no known public exploits or significant community discussion, its potential for system-level compromise warrants attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:android:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.