CVE-2026-20456
Analyzed
Analyzed - Analysis Complete
WLAN STA Driver Missing Bounds Check Leads to System Crash
Publication date: 2026-06-01
Last updated on: 2026-06-01
Assigner: MediaTek, Inc.
Description
Description
In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480851; Issue ID: MSV-6338.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mediatek | mt7902_firmware | * |
| mediatek | mt7920_firmware | * |
| mediatek | mt7921_firmware | * |
| mediatek | mt7922_firmware | * |
| mediatek | mt7925_firmware | * |
| mediatek | mt7927_firmware | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |