Executive brief
A vulnerability in the MediaTek wlan STA driver, which manages wireless station connections, can cause a system crash. A local user with standard execution privileges could exploit this flaw to trigger a denial of service, potentially disrupting device operations and connectivity. No user interaction is required for this exploit to occur.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the MediaTek wlan STA driver due to a missing bounds check. A local attacker with user-level execution privileges can exploit this flaw to trigger a system crash, resulting in a denial of service (DoS). The vulnerability does not require user interaction for exploitation. MediaTek has released a patch under Patch ID WCNCR00480851 to address this issue.
Affected products
- MediaTek wlan STA driver
Timeline
- 2026-06-01: disclosed
- 2026-06-01: advisory