CVE-2026-20482
Received Received - Intake

WLAN STA Firmware Logging Denial of Service

Vulnerability report for CVE-2026-20482, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-03

Last updated on: 2026-08-03

Assigner: MediaTek, Inc.

Description

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-03
Last Modified
2026-08-03
Generated
2026-08-03
AI Q&A
2026-08-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediatek wlan_sta_fw *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in wlan STA FW allows a system to become unresponsive due to excessive logging. It can cause a remote denial of service attack from nearby devices without requiring additional permissions or user interaction.

Detection Guidance

This vulnerability involves a system becoming unresponsive due to logging in wlan STA FW. Detection may require monitoring for unresponsive wireless network interfaces or excessive logging activity. Check system logs for wlan-related errors or crashes. Verify if the affected firmware version (Patch ID: WCNCR00486814) is installed.

Impact Analysis

The vulnerability could make your device unresponsive, disrupting network connectivity or other wireless functions. It may require a restart to recover normal operation.

Compliance Impact

This vulnerability could lead to a denial of service by making the system unresponsive due to excessive logging. While it does not directly impact data confidentiality or integrity, prolonged unavailability may affect compliance with standards requiring system availability, such as GDPR's requirement for timely data processing or HIPAA's access controls.

Mitigation Strategies

Apply the patch identified as WCNCR00486814 to the mediatek wlan_sta_fw component to address the logging-related system unresponsiveness issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20482. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart