CRITICAL🇵🇱 Wersja polska

CVE-2026-24804

CVSS 9.2v4.0pub. 2026-01-27upd. 2026-04-15

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.

🤖 AI Analysis
How it works

The bug is located in the bn_lib.C file belonging to the common module of the mt7603e Wi-Fi driver, which is part of the package/lean/mt/drivers/mt7603e/src/mt7603_wifi package in the lede project. The program logic contains a loop whose termination condition is unreachable, meaning that once a specific execution path is entered, the process never exits the loop. A remote attacker without authentication and without user interaction can trigger this path over the network (AV:N, PR:N, UI:N), causing process or system suspension.

Impact

An attacker can cause permanent service unavailability (DoS) on a vulnerable device, resulting in loss of network connectivity for both the device and its connected clients (VA:H, SA:H). Recovery of functionality likely requires manual restart of the device.

Mitigation & patch

Patches available from the vendor should be applied according to references (pull request published at https://github.com/coolsnowwolf/lede/pull/13368). Users should update firmware to a version higher than r25.10.1 once the patched build is released.

Who is affected

The lede project by coolsnowwolf in all versions up to and including r25.10.1 that use the mt7603e Wi-Fi driver.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Amber
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References