CVE-2026-20419
BaseFortify
Publication date: 2026-02-02
Last updated on: 2026-02-05
Assigner: MediaTek, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mediatek | nbiot_sdk | to 3.6 (inc) |
| mediatek | software_development_kit | to 7.6.7.2 (inc) |
| mediatek | mt6890 | * |
| mediatek | mt6989tb | * |
| mediatek | mt7902 | * |
| mediatek | mt7915 | * |
| mediatek | mt7916 | * |
| mediatek | mt7920 | * |
| mediatek | mt7921 | * |
| mediatek | mt7922 | * |
| mediatek | mt7925 | * |
| mediatek | mt7927 | * |
| mediatek | mt7981 | * |
| mediatek | mt7986 | * |
| mediatek | mt8196 | * |
| mediatek | mt8668 | * |
| mediatek | mt8676 | * |
| mediatek | mt8678 | * |
| mediatek | mt8775 | * |
| mediatek | mt8791t | * |
| mediatek | mt8792 | * |
| mediatek | mt8793 | * |
| mediatek | mt8796 | * |
| mediatek | mt8873 | * |
| mediatek | mt8883 | * |
| mediatek | mt8893 | * |
| mediatek | mt8910 | * |
| openwrt | openwrt | 19.07.0 |
| openwrt | openwrt | 21.02.0 |
| mediatek | mt6890 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-754 | The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in wlan AP/STA firmware where an uncaught exception can cause the system to become unresponsive. It can be exploited remotely by an attacker in close proximity without needing any user interaction or additional execution privileges.
How can this vulnerability impact me? :
The impact of this vulnerability is a denial of service (DoS) condition, where the affected system becomes unresponsive, potentially disrupting network connectivity or device functionality.
What immediate steps should I take to mitigate this vulnerability?
Apply the patches identified as WCNCR00461663 and WCNCR00463309 to the affected wlan AP/STA firmware to mitigate the vulnerability.