Ad

CVE-2026-20436

MEDIUM CVSS 3.1: 6.7 EPSS 0.02%
Updated Mar 03, 2026
Mediatek
Parameter Value
CVSS 6.7 (MEDIUM)
Affected Versions before 3.8
Type CWE-120 (Buffer Copy without Checking Size)
Vendor Mediatek
Public PoC No

In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation.

Patch ID: WCNCR00473802; Issue ID: MSV-5970.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v3.1

Vulnerable Products 8

Configuration From (including) Up to (excluding)
Mediatek Nbiot_Sdk
cpe:2.3:a:mediatek:nbiot_sdk:*:*:*:*:*:*:*:*
<= 3.8
Mediatek Mt7902
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
Mediatek Mt7920
cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:*
Mediatek Mt7921
cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*
Mediatek Mt7922
cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:*
Mediatek Mt7925
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
Mediatek Mt7927
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
Mediatek Mt8696
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*