CVE-2026-20452
Description
Heap buffer overflow in MediaTek wlan AP driver allows adjacent remote code execution with user privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Heap buffer overflow in MediaTek wlan AP driver allows adjacent remote code execution with user privileges.
Vulnerability
A heap buffer overflow (CWE-122) exists in the wlan AP driver of multiple MediaTek chipsets, including MT6890, MT7615, MT7915, MT7916, MT7981, MT7986, MT7990, MT7992, and MT7993 [1]. The vulnerability is triggered when processing crafted wireless frames, leading to memory corruption. The driver runs with user execution privileges, and no user interaction is required for exploitation. The issue is identified as MSV-6295 with patch ID WCNCR00480138.
Exploitation
An attacker within wireless range (adjacent network) can send a specially crafted frame to the target device's wlan AP driver. No authentication or user interaction is needed. The heap overflow occurs during frame processing, corrupting adjacent memory.
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the wlan AP driver, which operates with user privileges. This can lead to memory corruption, information disclosure, and potential further compromise of the device.
Mitigation
MediaTek has released a security patch (WCNCR00480138) to device OEMs, who are responsible for distributing firmware updates. Affected chipsets are listed in the June 2026 Product Security Bulletin [1]. Users should apply updates from their device manufacturer as soon as available. No workarounds are documented, and no active exploitation has been reported as of the bulletin date.
AI Insight generated on Jun 1, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1News mentions
1- MediaTek: Four CVEs Disclosed — Three GenieZone TEE Bugs and a WLAN Driver OverflowVypr Intelligence · Jun 1, 2026