Out of Bounds Write in MediaTek Wlan STA Driver
CVE-2026-20423

7.8HIGH

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
2 March 2026

What is CVE-2026-20423?

A security vulnerability exists in the MediaTek wlan STA driver, caused by a missing bounds check that may allow for an out of bounds write. This flaw could be exploited locally by an attacker with user execution privileges. Notably, the exploitation does not require user interaction, thus presenting an increased risk for affected systems. The vulnerability has been addressed in patch WCNCR00465314, which is recommended for users to apply as a preventive measure.

Affected Version(s)

MediaTek chipset MT7902

MediaTek chipset MT7920

MediaTek chipset MT7921

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.