cbcvebase.

Mediatek Inc Mediatek Chipset vulnerabilities

91 known vulnerabilities affecting mediatek_inc/mediatek_chipset.

Total CVEs
91
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH25MEDIUM64

Vulnerabilities

Page 1 of 5
CVE-2026-20418P3CRITICALCVSS 9.8vMT7931vMT79332026-02-02
CVE-2026-20418 [CRITICAL] CWE-787 CVE-2026-20418: In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465153; Issue ID: MSV-4927.
nvd
CVE-2026-20408P3HIGHCVSS 8.8vMT6890vMT7615+4 more2026-02-02
CVE-2026-20408 [HIGH] CWE-122 CVE-2026-20408: In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to r In wlan, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00461651; Issue ID: MSV-4758.
nvd
CVE-2026-20433P3HIGHCVSS 8.8vMT2735vMT2737+60 more2026-04-07
CVE-2026-20433 [HIGH] CWE-787 CVE-2026-20433: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.
nvd
CVE-2026-20430P3HIGHCVSS 8.8vMT6890vMT7915+3 more2026-03-02
CVE-2026-20430 [HIGH] CWE-787 CVE-2026-20430: In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00467553; Issue ID: MSV-5151.
nvd
CVE-2026-20407P3CRITICALCVSS 9.3vMT7902vMT7920+4 more2026-02-02
CVE-2026-20407 [CRITICAL] CWE-787 CVE-2026-20407: In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905.
nvd
CVE-2026-20452P3HIGHCVSS 8.0vMT6890vMT7615+7 more2026-06-01
CVE-2026-20452 [HIGH] CWE-122 CVE-2026-20452: In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could l In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.
nvd
CVE-2026-20401P3HIGHCVSS 7.5vMT2735vMT6833+17 more2026-02-02
CVE-2026-20401 [HIGH] CWE-617 CVE-2026-20401: In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote d In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738310; Issue ID: MSV-5933.
nvd
CVE-2026-20458P3HIGHCVSS 7.5vMT2716vMT2737+62 more2026-07-01
CVE-2026-20458 [HIGH] CWE-787 CVE-2026-20458: In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to re In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
nvd
CVE-2026-20432P3HIGHCVSS 8.0vMT2735vMT2737+56 more2026-04-07
CVE-2026-20432 [HIGH] CWE-787 CVE-2026-20432: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.
nvd
CVE-2026-20434P3HIGHCVSS 7.5vMT2735vMT2737+92 more2026-03-02
CVE-2026-20434 [HIGH] CWE-787 CVE-2026-20434: In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY00782946; Issue ID: MSV-4135.
nvd
CVE-2026-20416P3HIGHCVSS 7.2vMT6991vMT6993+2 more2026-03-02
CVE-2026-20416 [HIGH] CWE-787 CVE-2026-20416: In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to l In pcie, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315038 / ALPS10340155; Issue ID: MSV-5155.
nvd
CVE-2026-20423P3HIGHCVSS 7.8vMT7902vMT7920+4 more2026-03-02
CVE-2026-20423 [HIGH] CWE-749 CVE-2026-20423: In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This coul In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.
nvd
CVE-2025-20780P3HIGHCVSS 7.8vMT6739vMT6761+43 more2026-01-06
CVE-2025-20780 [HIGH] CWE-416 CVE-2025-20780: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10184061; Issue ID: MSV-4712.
nvd
CVE-2025-20799P3HIGHCVSS 7.8vMT6899vMT6991+2 more2026-01-06
CVE-2025-20799 [HIGH] CWE-416 CVE-2025-20799: In c2ps, there is a possible memory corruption due to use after free. This could lead to local escal In c2ps, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10274607; Issue ID: MSV-5049.
nvd
CVE-2025-20781P3HIGHCVSS 7.8vMT6739vMT6761+43 more2026-01-06
CVE-2025-20781 [HIGH] CWE-415 CVE-2025-20781: In display, there is a possible memory corruption due to use after free. This could lead to local es In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10182914; Issue ID: MSV-4699.
nvd
CVE-2026-20455P3HIGHCVSS 7.8vMT6739vMT6761+34 more2026-06-01
CVE-2026-20455 [HIGH] CWE-787 CVE-2026-20455: In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784.
nvd
CVE-2026-20409P3HIGHCVSS 7.8vMT6897vMT69892026-02-02
CVE-2026-20409 [HIGH] CWE-787 CVE-2026-20409: In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to In imgsys, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10363246; Issue ID: MSV-5779.
nvd
CVE-2026-20412P3HIGHCVSS 7.8vMT6878vMT6879+22 more2026-02-02
CVE-2026-20412 [HIGH] CWE-787 CVE-2026-20412: In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead In cameraisp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5733.
nvd
CVE-2026-20411P3HIGHCVSS 7.8vMT6878vMT6879+22 more2026-02-02
CVE-2026-20411 [HIGH] CWE-416 CVE-2026-20411: In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to In cameraisp, there is a possible escalation of privilege due to use after free. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10351676; Issue ID: MSV-5737.
nvd
CVE-2025-20797P3HIGHCVSS 7.8vMT2718vMT6765+32 more2026-01-06
CVE-2025-20797 [HIGH] CWE-121 CVE-2025-20797: In battery, there is a possible out of bounds write due to a missing bounds check. This could lead t In battery, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10315812; Issue ID: MSV-5534.
nvd