Description
In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
Published: 2026-08-03
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the WLAN STA firmware of MediaTek chipsets, where excessive or unbounded logging can cause the system to become unresponsive. This results in a denial‑of‑service condition that can be triggered remotely from a nearby or adjacent source without requiring any additional privileges or user interaction. The weakness corresponds to CWE‑770, representing failure to control memory or resource consumption.

Affected Systems

The affected products are MediaTek chipsets running the WLAN STA firmware. No specific firmware versions are listed in the provided data, so all current releases that include the vulnerable logging mechanism are at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a somewhat lower likelihood of exploitation. However, the attack vector is remote (proximal/adjacent) and no credentials are required, making it accessible to any nearby device. Because the impact is a complete denial of service, the risk to availability is high, and a timely patch is strongly recommended.

Generated by OpenCVE AI on August 4, 2026 at 21:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware update that includes patch ID WCNCR00486814.
  • Reduce or temporarily disable the logging mechanism in the WLAN STA firmware to prevent excessive resource consumption.
  • Configure local network defenses (e.g., firewall rules or segmentation) to block traffic from nearby devices that could exploit the attack vector.

Generated by OpenCVE AI on August 4, 2026 at 21:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt7902
Mediatek mt7902 Firmware
Mediatek mt7921
Mediatek mt7921 Firmware
Mediatek mt7922
Mediatek mt7922 Firmware
Mediatek mt8518s
Mediatek mt8518s Firmware
Mediatek mt8532
Mediatek mt8532 Firmware
CPEs cpe:2.3:h:mediatek:mt7902:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7921:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt7922:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8518s:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8532:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7902_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7921_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt7922_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8518s_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8532_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt7902
Mediatek mt7902 Firmware
Mediatek mt7921
Mediatek mt7921 Firmware
Mediatek mt7922
Mediatek mt7922 Firmware
Mediatek mt8518s
Mediatek mt8518s Firmware
Mediatek mt8532
Mediatek mt8532 Firmware

Tue, 04 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title WLAN STA Firmware Logging Causes Remote Denial of Service on MediaTek Chipsets

Mon, 03 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00486814; Issue ID: MSV-6824.
Weaknesses CWE-770
References

Subscriptions

Mediatek Mt7902 Mt7902 Firmware Mt7921 Mt7921 Firmware Mt7922 Mt7922 Firmware Mt8518s Mt8518s Firmware Mt8532 Mt8532 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T19:43:53.037Z

Reserved: 2025-11-03T01:30:59.021Z

Link: CVE-2026-20482

cve-icon Vulnrichment

Updated: 2026-08-03T19:43:48.860Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:43.317

Modified: 2026-08-19T17:01:34.653

Link: CVE-2026-20482

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:00:07Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling