The Quantenna Wi-Fi chips ship with an unauthenticated...
Critical severity
Unreviewed
Published
Jun 8, 2025
to the GitHub Advisory Database
•
Updated Jun 8, 2025
Description
Published by the National Vulnerability Database
Jun 8, 2025
Published to the GitHub Advisory Database
Jun 8, 2025
Last updated
Jun 8, 2025
The Quantenna Wi-Fi chips ship with an unauthenticated telnet interface by default. This is an instance of CWE-306, "Missing Authentication for Critical Function," and is estimated as a CVSS 9.1 ( CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) https://www.first.org/cvss/calculator/3-1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) .
This issue affects Quantenna Wi-Fi chipset through version 8.0.0.28 of the latest SDK, and appears to be unpatched at the time of this CVE record's first publishing, though the vendor has released a best practices guide for implementors of this chipset.
References