Executive brief
A vulnerability exists in the MediaTek wireless access point (WLAN AP) driver, which is responsible for managing Wi-Fi connectivity on affected devices. An attacker within physical proximity or on the same local network could potentially execute unauthorized code on the device. This could lead to a complete compromise of the device, potentially allowing an attacker to intercept network traffic or gain a foothold in the local network.
Technical details
A heap-based buffer overflow (CWE-122) exists in the MediaTek WLAN AP driver. The vulnerability allows for memory corruption which can be leveraged for remote code execution (RCE) by an attacker located in the proximal or adjacent network (e.g., via Wi-Fi). While exploitation requires 'User' execution privileges, it notably requires no user interaction. MediaTek has released a patch under Patch ID WCNCR00480138 to address this issue.
Affected products
- MediaTek WLAN AP Driver
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory