CVE-2026-20456
WLAN STA Driver Missing Bounds Check Leads to System Crash
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: MediaTek, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mediatek | wlan_sta_driver | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the wlan STA driver where a missing bounds check can cause a system crash.
It can be exploited locally without any user interaction and requires only user execution privileges.
The issue may lead to a denial of service condition on the affected system.
How can this vulnerability impact me? :
The primary impact of this vulnerability is a local denial of service, which means the affected system could crash or become unresponsive.
Since exploitation does not require user interaction and only needs user execution privileges, an attacker with local access could cause system instability or downtime.