Description
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970.
Published: 2026-03-02
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Escalation of Privilege
Action: Apply Patch
AI Analysis

Impact

A missing bounds check in the MediaTek WLAN STA driver allows a malicious actor who already holds system-level privileges to incrementally raise their own privileges without requiring any further user interaction. This flaw can be exploited locally on devices running the affected driver code, potentially granting the attacker full control over the system. The vulnerability is a classic buffer overflow, categorized under CWE‑120, which can corrupt memory and bypass access controls.

Affected Systems

The flaw affects MediaTek chipsets that implement the WLAN STA driver, including models MT7902, MT7920, MT7921, MT7922, MT7925, MT7927, and MT8696. The CVE source does not list specific firmware or driver version numbers, so any device using the affected driver code is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.7 indicates medium severity for local privilege escalation. Exploitation requires an attacker to already have system-level privileges on the target device, which may result from an earlier compromise or hard‑coded vulnerability. The EPSS score of less than 1% suggests a low probability of exploitation in the wild, and the vulnerability is not currently listed in the CISA KEV catalog. Once the escalation is achieved, the attacker could fully compromise the device, for example by modifying firmware, installing malicious software, or executing arbitrary commands.

Generated by OpenCVE AI on April 16, 2026 at 05:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor-supplied patch WCNCR00473802 to the MediaTek WLAN STA driver to eliminate the bounds‑check flaw.
  • Disable the WLAN STA functionality or the driver module on affected devices until the patch is deployed to prevent the vulnerability from being exploitable.
  • Reduce local system privileges to the minimum required for legitimate users and processes, limiting the potential impact of any future local exploitation.

Generated by OpenCVE AI on April 16, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 06:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Missing Bounds Check in MediaTek WLAN STA Driver

Tue, 03 Mar 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt7902
Mediatek mt7920
Mediatek mt7921
Mediatek mt7922
Mediatek mt7925
Mediatek mt7927
Mediatek mt8696
Mediatek nbiot Sdk
CPEs cpe:2.3:a:mediatek:nbiot_sdk:*:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7920:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7925:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7927:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8696:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt7902
Mediatek mt7920
Mediatek mt7921
Mediatek mt7922
Mediatek mt7925
Mediatek mt7927
Mediatek mt8696
Mediatek nbiot Sdk

Mon, 02 Mar 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 02 Mar 2026 09:00:00 +0000

Type Values Removed Values Added
Description In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00473802; Issue ID: MSV-5970.
Weaknesses CWE-120
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-03-30T13:05:41.183Z

Reserved: 2025-11-03T01:30:59.011Z

Link: CVE-2026-20436

cve-icon Vulnrichment

Updated: 2026-03-02T13:34:17.334Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-02T09:16:16.743

Modified: 2026-03-03T12:49:52.000

Link: CVE-2026-20436

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T06:00:10Z

Weaknesses