Heap-based buffer overflow in MediaTek products - CVE-2026-20452
Published: June 1, 2026
Vulnerability identifier: #VU133127
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-20452
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause memory corruption.
The vulnerability exists due to heap-based buffer overflow in wlan when processing input. A local user can trigger the vulnerable condition to cause memory corruption.
Affected software
MT6890
MT7615
MT7915
MT7916
MT7981
MT7986
MT7990
MT7992
MT7993
MT7615
MT7915
MT7916
MT7981
MT7986
MT7990
MT7992
MT7993
How to mitigate CVE-2026-20452
Install security update from vendor's website.