In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905.
The error classified as CWE-787 (out-of-bounds write) results from missing bounds checking in the WLAN STA driver. An attacker with user execution privileges can trigger a write operation outside the designated memory area, leading to privilege escalation. No user interaction is required to perform the attack. The attack vector is local (AV:L), however, the scope of the vulnerability extends beyond the component boundary (Scope: Changed).
Successful exploitation of this vulnerability allows an attacker to perform local privilege escalation to a higher level, which may result in complete system takeover, including breach of confidentiality, integrity, and data availability.
Apply patch with identifier WCNCR00464377 (Issue ID: MSV-4905) in accordance with MediaTek's security bulletin from February 2026, available at: https://corp.mediatek.com/product-security-bulletin/February-2026. Contact the end device manufacturer to obtain firmware updates containing the indicated fix.
The vulnerability affects devices equipped with MediaTek chips: MT7902, MT7920, MT7921, MT7922, and the NB-IoT SDK platform (Nbiot SDK) — specific firmware versions indicated in manufacturer references.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HMediatek Mt7902
HWMediatekall versionsMediatek Mt7920
HWMediatekall versionsMediatek Mt7921
HWMediatekall versionsMediatek Mt7922
HWMediatekall versionsMediatek Mt7925
HWMediatekall versionsMediatek Mt7927
HWMediatekall versionsMediatek Nbiot Sdk
APPMediatek≤ 3.8
Related vulnerabilities
MediaTek Bluetooth – heap buffer overflow umożliwiający privilege escalation
Przepełnienie bufora sterty w sterowniku Bluetooth — MediaTek MT79xx
Out-of-bounds write w WLAN STA FW MediaTek — zdalne RCE
MediaTek WLAN Driver — błąd zapisu poza buforem umożliwiający RCE
MediaTek WLAN Driver — zapis poza granicami bufora umożliwia RCE