CRITICAL🇵🇱 Wersja polska

CVE-2026-20407

CVSS 9.3v3.1pub. 2026-02-02upd. 2026-02-04

In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905.

🤖 AI Analysis
How it works

The error classified as CWE-787 (out-of-bounds write) results from missing bounds checking in the WLAN STA driver. An attacker with user execution privileges can trigger a write operation outside the designated memory area, leading to privilege escalation. No user interaction is required to perform the attack. The attack vector is local (AV:L), however, the scope of the vulnerability extends beyond the component boundary (Scope: Changed).

Impact

Successful exploitation of this vulnerability allows an attacker to perform local privilege escalation to a higher level, which may result in complete system takeover, including breach of confidentiality, integrity, and data availability.

Mitigation & patch

Apply patch with identifier WCNCR00464377 (Issue ID: MSV-4905) in accordance with MediaTek's security bulletin from February 2026, available at: https://corp.mediatek.com/product-security-bulletin/February-2026. Contact the end device manufacturer to obtain firmware updates containing the indicated fix.

Who is affected

The vulnerability affects devices equipped with MediaTek chips: MT7902, MT7920, MT7921, MT7922, and the NB-IoT SDK platform (Nbiot SDK) — specific firmware versions indicated in manufacturer references.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Mediatek Mt7902

    HW
    Mediatek
    all versions
  • Mediatek Mt7920

    HW
    Mediatek
    all versions
  • Mediatek Mt7921

    HW
    Mediatek
    all versions
  • Mediatek Mt7922

    HW
    Mediatek
    all versions
  • Mediatek Mt7925

    HW
    Mediatek
    all versions
  • Mediatek Mt7927

    HW
    Mediatek
    all versions
  • Mediatek Nbiot Sdk

    APP
    Mediatek
    ≤ 3.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-20680CRITICAL9.8PL ✓same product

MediaTek Bluetooth – heap buffer overflow umożliwiający privilege escalation

CVE-2025-20672CRITICAL9.8PL ✓same product

Przepełnienie bufora sterty w sterowniku Bluetooth — MediaTek MT79xx

CVE-2024-20148CRITICAL9.8PL ✓same product

Out-of-bounds write w WLAN STA FW MediaTek — zdalne RCE

CVE-2024-20101CRITICAL9.8PL ✓same product

MediaTek WLAN Driver — błąd zapisu poza buforem umożliwiający RCE

CVE-2024-20100CRITICAL9.8PL ✓same product

MediaTek WLAN Driver — zapis poza granicami bufora umożliwia RCE