{"id": "CVE-2026-20452", "cveTags": [], "metrics": {"ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"id": "CVE-2026-20452", "role": "CISA Coordinator", "options": [{"exploitation": "none"}, {"automatable": "no"}, {"technicalImpact": "total"}], "version": "2.0.3", "timestamp": "2026-06-01T00:00:00+00:00"}}], "cvssMetricV31": [{"type": "Secondary", "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "cvssData": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 8.0, "attackVector": "ADJACENT_NETWORK", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "NONE", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "LOW", "confidentialityImpact": "HIGH"}, "impactScore": 5.9, "exploitabilityScore": 2.1}]}, "affected": [{"source": "security@mediatek.com", "affectedData": [{"vendor": "MediaTek, Inc.", "product": "MediaTek chipset", "versions": [{"status": "affected", "version": "MT6890"}, {"status": "affected", "version": "MT7615"}, {"status": "affected", "version": "MT7915"}, {"status": "affected", "version": "MT7916"}, {"status": "affected", "version": "MT7981"}, {"status": "affected", "version": "MT7986"}, {"status": "affected", "version": "MT7990"}, {"status": "affected", "version": "MT7992"}, {"status": "affected", "version": "MT7993"}], "defaultStatus": "unaffected"}]}], "published": "2026-06-01T04:16:21.753", "references": [{"url": "https://corp.mediatek.com/product-security-bulletin/June-2026", "tags": ["Vendor Advisory"], "source": "security@mediatek.com"}], "vulnStatus": "Analyzed", "weaknesses": [{"type": "Secondary", "source": "security@mediatek.com", "description": [{"lang": "en", "value": "CWE-122"}]}], "descriptions": [{"lang": "en", "value": "In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295."}, {"lang": "es", "value": "En el controlador de AP WLAN, existe una posible corrupci\u00f3n de memoria debido a un desbordamiento de b\u00fafer en el heap. Esto podr\u00eda conducir a una ejecuci\u00f3n de c\u00f3digo remota (pr\u00f3xima/adyacente) con privilegios de ejecuci\u00f3n de usuario necesarios. No se necesita interacci\u00f3n del usuario para la explotaci\u00f3n. ID del parche: WCNCR00480138; ID del problema: MSV-6295."}], "lastModified": "2026-07-22T07:10:00.107", "configurations": [{"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BB9AC17B-5ED8-4B58-A7A0-B146DD1DD244"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "171D1C08-F055-44C0-913C-AA2B73AF5B72"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7615_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "209D0B1B-C27E-429E-ABC0-894E105814D1"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "05748BB1-0D48-4097-932E-E8E2E574FD8D"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7915_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E6C54AA5-6C50-4223-B433-4C14AD4E96A3"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "3AB22996-9C22-4B6C-9E94-E4C055D16335"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7916_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5318B13A-DB70-4017-AB82-2C7F5144FCFF"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "DD5AA441-5381-4179-89EB-1642120F72B4"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7981_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "D70F8D77-FDEC-4AAE-B22C-4F05ED880C10"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "490CD97B-021F-4350-AEE7-A2FA866D5889"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7986_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8798F3AE-A468-49B0-AE1D-6F1E41C76085"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "40A9E917-4B34-403F-B512-09EEBEA46811"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7990_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E58E5724-B753-4E78-A5F3-4B9023A15637"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7990:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "4901B2A5-B0C8-4A0C-AC17-87D469744817"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7992_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8CB6DB8C-E756-4FAE-ADCC-CFE91C7C735E"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7992:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "50D01D7D-A88D-471D-A23A-42AF4DF82952"}], "operator": "OR"}], "operator": "AND"}, {"nodes": [{"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:o:mediatek:mt7993_firmware:-:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F389E2A1-CE3A-4826-A248-A9BCEF3088F4"}], "operator": "OR"}, {"negate": false, "cpeMatch": [{"criteria": "cpe:2.3:h:mediatek:mt7993:-:*:*:*:*:*:*:*", "vulnerable": false, "matchCriteriaId": "76653163-7627-4C63-A5E2-6277C0EFE23E"}], "operator": "OR"}], "operator": "AND"}], "sourceIdentifier": "security@mediatek.com"}