Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in coolsnowwolf lede (package/lean/mt/drivers/mt7603e/src/mt7603_wifi/common modules). This vulnerability is associated with program files bn_lib.C. This issue affects lede: through r25.10.1.
The bug is located in the bn_lib.C file belonging to the common module of the mt7603e Wi-Fi driver, which is part of the package/lean/mt/drivers/mt7603e/src/mt7603_wifi package in the lede project. The program logic contains a loop whose termination condition is unreachable, meaning that once a specific execution path is entered, the process never exits the loop. A remote attacker without authentication and without user interaction can trigger this path over the network (AV:N, PR:N, UI:N), causing process or system suspension.
An attacker can cause permanent service unavailability (DoS) on a vulnerable device, resulting in loss of network connectivity for both the device and its connected clients (VA:H, SA:H). Recovery of functionality likely requires manual restart of the device.
Patches available from the vendor should be applied according to references (pull request published at https://github.com/coolsnowwolf/lede/pull/13368). Users should update firmware to a version higher than r25.10.1 once the patched build is released.
The lede project by coolsnowwolf in all versions up to and including r25.10.1 that use the mt7603e Wi-Fi driver.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Amber