Out-of-Bounds Write Vulnerability in MediaTek WLAN AP Driver
CVE-2026-20465

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
3 August 2026

What is CVE-2026-20465?

A flaw in the MediaTek WLAN Access Point (AP) driver has been identified, where a lack of proper bounds checking can lead to out-of-bounds write vulnerabilities. This issue allows for potential remote escalation of privileges, requiring no additional execution privileges or user interaction, thus posing significant security risks for devices running affected versions of the driver. A patch has been released to address this vulnerability, denoted by Patch ID WCNCR00489200.

Affected Version(s)

MediaTek chipset MT6890

MediaTek chipset MT7915

MediaTek chipset MT7916

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.