CVE-2026-20436

Plain English Summary

AI-powered analysis for quick understanding

This vulnerability allows an attacker with system privileges to gain even higher privileges on devices using the MediaTek NB-IoT SDK, potentially giving them more control over the system. The attacker does not need any user interaction to exploit this flaw, but they must already have access to the system.

Technical Description

In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970.

CVSS Vector Analysis

Attack VectorLocal
Attack ComplexityLow
Privileges RequiredHigh
User InteractionNone
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactHigh
ScopeUnchanged

Vector String

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Exploit Resources

Search for proof-of-concept code and exploit modules

Official References