CVE-2026-20452

In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00480138; Issue ID: MSV-6295.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mediatek:mt7615_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mediatek:mt7915_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mediatek:mt7916_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mediatek:mt7981_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mediatek:mt7986_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mediatek:mt7990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7990:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mediatek:mt7992_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7992:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mediatek:mt7993_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7993:-:*:*:*:*:*:*:*

History

01 Jun 2026, 18:12

Type Values Removed Values Added
References () https://corp.mediatek.com/product-security-bulletin/June-2026 - () https://corp.mediatek.com/product-security-bulletin/June-2026 - Vendor Advisory
CPE cpe:2.3:o:mediatek:mt7981_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7992_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7916_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7990_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7993:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7986:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7915:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7993_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7915_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7986_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7992:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7615_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7916:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7615:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7981:-:*:*:*:*:*:*:*
First Time Mediatek mt7615 Firmware
Mediatek mt7992
Mediatek mt7986
Mediatek mt7986 Firmware
Mediatek
Mediatek mt6890
Mediatek mt7993 Firmware
Mediatek mt7981 Firmware
Mediatek mt7915 Firmware
Mediatek mt6890 Firmware
Mediatek mt7990
Mediatek mt7915
Mediatek mt7992 Firmware
Mediatek mt7916
Mediatek mt7981
Mediatek mt7993
Mediatek mt7615
Mediatek mt7990 Firmware
Mediatek mt7916 Firmware

01 Jun 2026, 13:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.0

01 Jun 2026, 04:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 04:16

Updated : 2026-06-01 18:12


NVD link : CVE-2026-20452

Mitre link : CVE-2026-20452

CVE.ORG link : CVE-2026-20452


JSON object : View

Products Affected

mediatek

  • mt7916
  • mt7990_firmware
  • mt7986_firmware
  • mt6890_firmware
  • mt7615_firmware
  • mt7981
  • mt7993
  • mt7993_firmware
  • mt7992
  • mt7990
  • mt7915
  • mt7916_firmware
  • mt7915_firmware
  • mt7986
  • mt7615
  • mt7992_firmware
  • mt6890
  • mt7981_firmware
CWE
CWE-122

Heap-based Buffer Overflow