Wi-Fi Firmware Security Bug Could Affect Billions of Game Consoles, Laptops, and More, Researcher Says

Advertisement
By Jamshed Avari | Updated: 21 January 2019 13:55 IST
Highlights
  • The security vulnerability was discovered by research firm Embedi
  • Billions of Wi-Fi-enabled devices are potentially affected
  • An attacker would need to be in physical proximity of a target device

Photo Credit: Embedi

Security research firm Embedi has published a report about severe security vulnerabilities it has found in several Wi-Fi controller chips used by billions of the world's most popular Wi-Fi-enabled products. These include the Microsoft Xbox One, Sony PlayStation 4, and some laptop and smartphone models as well as several routers, embedded devices, and network access hardware. The bugs in question allow malicious attackers to force Wi-Fi-enabled devices to execute arbitrary code simply by being turned on, without requiring any action on the part of the device owner or user. The attack is triggered whenever an affected device searches for available Wi-Fi networks, which is something that is set to happen automatically and repeatedly.

The root of the problem lies in a real-time operating system called ThreadX, which is used as the embedded firmware for many Wi-Fi controllers including the popular Marvell Avastar family used as the subject of Embedi's research. There are four vulnerabilities in total, which exploit a memory corruption bug referred to as a “block pool overflow” in order to introduce the malicious code onto a device.

Advertisement

One of these bugs is specific to the widely used Marvell Avastar 88W8897 Wi-Fi controller, but the others can affect any device based on ThreadX using the same techniques. Embedi cites ThreadX's own website as the source of its statement that over six billion devices have been deployed running this firmware.

Because affected Wi-Fi devices are set to scan for new networks every five minutes, regardless of whether or not they are already connected to a Wi-Fi network, this bug “provides an opportunity to exploit devices literally with zero-click interaction at any state of wireless connection”, according to the published report. Once malicious code is introduced onto the Wi-Fi controller, other techniques could be exploited to send data to the device's application processor.

Advertisement

A hypothetical attacker would not need to know a target's Wi-Fi SSID name or password, and the target device only needs to be turned on. The attacker would need to broadcast the malicious packets from within physical range of the target device, though.

Embedi tested the vulnerabilities using a Valve Steamlink game streaming device, which is based on the GNU/Linux operating system and features an ARM SoC and the affected Marvell Wi-Fi controller. This device was chosen because it allowed for research tools to run without breaking DRM restrictions.

Advertisement

According to Embedi researcher Denis Selianin, who wrote the report, the vulnerabilities were disclosed to Marvell in early May 2018. He presented his findings and a proof of concept at the Zero Nights security conference in late November 2018 and has only just published all his research, including a video showing the attack in progress. As of now, no fixes have been issued but according to the November presentation, work was in progress.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Embedi, Wi Fi, Security
Advertisement
Popular Mobile Brands
  1. OnePlus 13s Gets a New 16GB RAM Option in India at This Price
  2. GTA 6 Is Getting an Official Soundtrack Album With 34 Original Tracks
  3. OnePlus 16 Complete Specifications Leaked by Tipster Months Ahead of Launch
  4. iPhone 18 Pro, iPhone 18 Pro Max Sale: India Price, Offers, and More
  5. Xiaomi 18 Pro Max Specifications Revealed by Geekbench Listing
  6. ColorOS 17 Introduced With the New Fluid Design: See Release Schedule
  7. OpenAI Details Six Concerning AI Model Behaviours in New Safety Reports
  8. Ai+ Pulse 2 FE Confirmed to Launch in India Soon
  9. Oppo K14 Plus 5G India Launch Teased; Flipkart Availability Confirmed
  10. Apple 18 Pro Max Manages Full Charge Faster Than iPhone 17 Pro Max, Video Reveals
  1. Google Pixel Drop September 2026 Adds Harry Potter Audiobook Packs, Scam Detection, and More
  2. Bungie Says It's Not Merging Marathon and Destiny Following Leaks, Confirms Content Updates Will Be Free
  3. BGMI Redeem Codes for September 18: Get Red Football Uniform (Wolves), Other Rewards for Free
  4. iPhone 18 Pro Max Charging Test Shows Major Speed Boost Over iPhone 17 Pro Max
  5. Lava Bold N4 Pro 5G Launched in India With 50-Megapixel Camera, 6,000mAh Battery: Price, Features
  6. OnePlus 13s 16GB RAM Variant Launched in India With Snapdragon 8 Elite Chipset: Price, Specifications
  7. Xiaomi 18 Pro Max Geekbench Listing Reveals Key Details Ahead of Launch
  8. MediaTek Dimensity 9600M Mobile Platform Launched With AI Efficiency Enhancements, Dual NPU Architecture
  9. Oppo K14 Plus 5G India Launch Officially Teased; Flipkart Availability Confirmed
  10. iQOO Pad Ultra Real-Life Images Leak Ahead of Launch; Cooling Vents, Narrow Bezels Revealed
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.