Junglewise Threat Intelligence

CVE-2026-20456: MediaTek wlan STA driver out-of-bounds write

CVE-2026-20456 · Severity: info · Published 2026-06-01

Vendors: MediaTek.

Executive brief

A vulnerability in the MediaTek wlan STA driver, which manages wireless station connections, can cause a system crash. A local user with standard execution privileges could exploit this flaw to trigger a denial of service, potentially disrupting device operations and connectivity. No user interaction is required for this exploit to occur.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the MediaTek wlan STA driver due to a missing bounds check. A local attacker with user-level execution privileges can exploit this flaw to trigger a system crash, resulting in a denial of service (DoS). The vulnerability does not require user interaction for exploitation. MediaTek has released a patch under Patch ID WCNCR00480851 to address this issue.

Affected products

  • MediaTek wlan STA driver

Timeline

  • 2026-06-01: disclosed
  • 2026-06-01: advisory

References