CVE-2026-20471
Received
Received - Intake
Out of Bounds Write in MediaTek Device Firmware
Vulnerability report for CVE-2026-20471, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-03
Last updated on: 2026-08-03
Assigner: MediaTek, Inc.
Description
Description
In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| mediatek | mt6880 | * |
| mediatek | mt6890 | * |
| mediatek | mt6990 | * |
| mediatek | mt6988 | * |
| mediatek | mt6986 | * |
| mediatek | mt6813 | * |
| mediatek | mt2735 | * |
| mediatek | mt2737 | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |