VYPR
Unrated severityNVD Advisory· Published Jun 1, 2026

CVE-2026-20452

CVE-2026-20452

Description

Heap buffer overflow in MediaTek wlan AP driver allows adjacent remote code execution with user privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Heap buffer overflow in MediaTek wlan AP driver allows adjacent remote code execution with user privileges.

Vulnerability

A heap buffer overflow (CWE-122) exists in the wlan AP driver of multiple MediaTek chipsets, including MT6890, MT7615, MT7915, MT7916, MT7981, MT7986, MT7990, MT7992, and MT7993 [1]. The vulnerability is triggered when processing crafted wireless frames, leading to memory corruption. The driver runs with user execution privileges, and no user interaction is required for exploitation. The issue is identified as MSV-6295 with patch ID WCNCR00480138.

Exploitation

An attacker within wireless range (adjacent network) can send a specially crafted frame to the target device's wlan AP driver. No authentication or user interaction is needed. The heap overflow occurs during frame processing, corrupting adjacent memory.

Impact

Successful exploitation allows the attacker to execute arbitrary code in the context of the wlan AP driver, which operates with user privileges. This can lead to memory corruption, information disclosure, and potential further compromise of the device.

Mitigation

MediaTek has released a security patch (WCNCR00480138) to device OEMs, who are responsible for distributing firmware updates. Affected chipsets are listed in the June 2026 Product Security Bulletin [1]. Users should apply updates from their device manufacturer as soon as available. No workarounds are documented, and no active exploitation has been reported as of the bulletin date.

References
  1. June 2026

AI Insight generated on Jun 1, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

1