Description
In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
Published: 2026-08-03
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out‑of‑bounds read has been found in the Wi‑Fi firmware of MediaTek chipsets. The flaw arises from a missing bounds check, allowing an attacker that already holds system‑level privileges to read memory beyond the intended buffer. This can expose sensitive data stored in the chip’s memory. No user interaction is required to exploit the vulnerability, making the attack feasible for a local adversary with elevated privileges.

Affected Systems

The affected products are MediaTek chipsets that include the vulnerable Wi‑Fi stack. Firmware patches identified as ALPS10960006, BORA00155314, BORA00155001, and BORA00154907 address the issue. No specific firmware version numbers are provided, but any device using MediaTek Wi‑Fi firmware prior to these patches is potentially impacted.

Risk and Exploitability

The vulnerability is not listed in the CISA KEV catalog and has an EPSS score of < 1 %, indicating limited data on exploitation probability. The CVSS score of 5.5 indicates a medium severity. The flaw requires the attacker to already possess system privileges, limiting the likely attack surface to local or privileged adversaries. Nevertheless, when this condition is met, the attacker can read confidential information, compromising the confidentiality of the device. Based on the available information, the risk is moderate, but it is significant enough to warrant patching.

Generated by OpenCVE AI on August 4, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest MediaTek firmware patch that includes ALPS10960006 and the related BORA patches.
  • Disable or limit Wi‑Fi functionality on affected devices until the official patch is applied, especially for devices operating with system privileges.
  • Apply the principle of least privilege to processes interacting with the Wi‑Fi stack, reducing the potential impact of local privilege exploits.

Generated by OpenCVE AI on August 4, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware
CPEs cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6990_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6990
Mediatek mt6990 Firmware

Tue, 04 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in MediaTek Wi‑Fi Stack Leading to Local Information Disclosure

Mon, 03 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in MediaTek Wi‑Fi Stack Leading to Local Information Disclosure

Mon, 03 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mediatek Chipset
Vendors & Products Mediatek
Mediatek mediatek Chipset

Mon, 03 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Description In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10960006 / BORA00155314, BORA00155001, BORA00154907; Issue ID: MSV-7570.
Weaknesses CWE-125
References

Subscriptions

Mediatek Mediatek Chipset Mt6890 Mt6890 Firmware Mt6988 Mt6988 Firmware Mt6990 Mt6990 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-08-03T18:57:13.814Z

Reserved: 2025-11-03T01:30:59.026Z

Link: CVE-2026-20494

cve-icon Vulnrichment

Updated: 2026-08-03T18:57:10.548Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-03T03:16:44.553

Modified: 2026-08-19T15:08:45.600

Link: CVE-2026-20494

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T22:15:03Z

Weaknesses