CVE-2026-20456
Analyzed Analyzed - Analysis Complete
WLAN STA Driver Missing Bounds Check Leads to System Crash

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: MediaTek, Inc.

Description
In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-21
AI Q&A
2026-06-01
EPSS Evaluated
2026-06-20
NVD
EUVD
Affected Vendors & Products
Showing 6 associated CPEs
Vendor Product Version / Range
mediatek mt7902_firmware *
mediatek mt7920_firmware *
mediatek mt7921_firmware *
mediatek mt7922_firmware *
mediatek mt7925_firmware *
mediatek mt7927_firmware *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Mitigation Strategies

To mitigate this vulnerability, apply the security patch identified as WCNCR00480851 provided by MediaTek.

Since the vulnerability is in the wlan STA driver and can cause a system crash due to a missing bounds check, updating the driver to the patched version is the recommended immediate step.

Executive Summary

This vulnerability exists in the wlan STA driver where a missing bounds check can cause a system crash.

It can be exploited locally without any user interaction and requires only user execution privileges.

The issue may lead to a denial of service condition on the affected system.

Impact Analysis

The primary impact of this vulnerability is a local denial of service, which means the affected system could crash or become unresponsive.

Since exploitation does not require user interaction and only needs user execution privileges, an attacker with local access could cause system instability or downtime.

Compliance Impact

The provided information does not specify any impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20456. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart