Executive brief
MediaTek chipsets include Wi-Fi firmware used in smartphones, tablets, and IoT devices. A flaw in the Wi-Fi station firmware can cause the system to become unresponsive due to excessive or malformed logging activity, disrupting network connectivity and device operation. An attacker within wireless range can trigger this condition without user interaction, causing a denial of service.
Technical details
A denial-of-service vulnerability exists in the MediaTek WLAN STA (station mode) firmware logging subsystem. The flaw allows an attacker to cause system unresponsiveness by triggering excessive or malformed logging operations. The attack is adjacent/proximal (requires wireless proximity) and requires no authentication or user interaction. An attacker can exploit this to render affected Wi-Fi-enabled devices unresponsive, disrupting network availability. MediaTek has provided a patch (WCNCR00486814) and notifies device OEMs to apply updates.
Affected products
- MediaTek WLAN STA Firmware
Timeline
- 2026-08-03: disclosed
- 2026-08-03: patched: Patch ID WCNCR00486814 available