mediatek

11 records · 0 with a public proof-of-concept

Disclosed vulnerabilities where the NVD names mediatek as an affected vendor, highest CVSS first.

  1. HIGH 8.8CVE-2026-20586

    In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS11383899; Issue ID: MSV…

    mt8910 firmware · mt8910 · mt2718 firmware · mt2718 · mt6768 firmware · mt6768

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.4CVE-2026-20524

    In apu, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249004; Issue ID: …

    mt6899 firmware · mt6899 · mt6993 firmware · mt6993 · mt8668 firmware · mt8668

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 8.4CVE-2026-20523

    In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249062; Issu…

    mt6881 firmware · mt6881 · mt6993 firmware · mt6993 · mt8188 firmware · mt8188

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 8.4CVE-2026-20522

    In neuropilot, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11249050; Issu…

    mt6881 firmware · mt6881 · mt6993 firmware · mt6993 · mt8188 firmware · mt8188

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 8.4CVE-2026-20521

    In Video HAL, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11375674; I…

    mt8910 firmware · mt8910 · mt2718 firmware · mt2718 · mt6768 firmware · mt6768

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.5CVE-2026-20526

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User i…

    mt2716 firmware · mt2716 · mt2735 firmware · mt2735 · mt2737 firmware · mt2737

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.5CVE-2026-20520

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User i…

    mt2716 firmware · mt2716 · mt2735 firmware · mt2735 · mt2737 firmware · mt2737

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.5CVE-2026-20519

    In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User i…

    mt6833 firmware · mt6833 · mt6835 firmware · mt6835 · mt6853 firmware · mt6853

    AI risk analysis on Exploit-DB.ai →

  9. MEDIUM 5.5CVE-2026-20543

    In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-67…

    mt2716 firmware · mt2716 · mt2735 firmware · mt2735 · mt2737 firmware · mt2737

    AI risk analysis on Exploit-DB.ai →

  10. MEDIUM 5.3CVE-2026-20527

    In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is…

    mt2716 firmware · mt2716 · mt2735 firmware · mt2735 · mt2737 firmware · mt2737

    AI risk analysis on Exploit-DB.ai →

  11. MEDIUM 5.3CVE-2026-20525

    In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction…

    mt2716 firmware · mt2716 · mt6835 firmware · mt6835 · mt6858 firmware · mt6858

    AI risk analysis on Exploit-DB.ai →