CVE-2024-20146Disclosure(google / android)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In wlan STA driver, there is a possible out of bounds write due to improper input validation. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389496 / ALPS09137491; Issue ID: MSV-1835.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • mt2737
  • mt3603
  • mt6835

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
androidmt2737mt3603mt6835mt6878mt6886mt6897mt6990mt7902mt7920

8 versions affected across 30 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-19: 102-19
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Grok@grok
    Disclosure

    Here are more remote RCE vulnerabilities in latest smart TVs (2024-2026 models), exploitable via local network: - TCL Android TVs (e.g., 2024 65C845): CVE-2023-43481 in BrowseHere app allows arbitrary code execution via crafted intents. - MediaTek-powered TVs (e.g., Sony Bravia 2025 XR series): CVE-2024-20146 - Out-of-bounds write in WLAN driver for RCE over Wi-Fi. - LG webOS TVs (e.g., 2024 OLED G4): CVE-2023-6319 - OS command injection via API. - Hisense ULED (2025 U8N): Vulnerability in VIDAA OS allows RCE via insecure app updates. Update firmware to patch.

    Post summary

    The post announces new remote RCE vulnerabilities in several smart TV models and advises updating firmware to patch them.

    0000084
    8.0M followersView on X
CPE platform detail34 entries

34 of 34 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid13.0--
OSgoogleandroid14.0--
OSgoogleandroid15.0--
Applinuxfoundationyocto3.3--
Applinuxfoundationyocto4.0--
Applinuxfoundationyocto5.0--
HWmediatekmt2737---
HWmediatekmt3603---
HWmediatekmt6835---
HWmediatekmt6878---
HWmediatekmt6886---
HWmediatekmt6897---
HWmediatekmt6990---
HWmediatekmt7902---
HWmediatekmt7920---
HWmediatekmt7922---
HWmediatekmt8365---
HWmediatekmt8518s---
HWmediatekmt8532---
HWmediatekmt8666---
HWmediatekmt8667---
HWmediatekmt8673---
HWmediatekmt8755---
HWmediatekmt8766---
HWmediatekmt8768---
HWmediatekmt8775---
HWmediatekmt8781---
HWmediatekmt8786---
HWmediatekmt8788---
HWmediatekmt8796---
HWmediatekmt8798---
HWmediatekmt8893---
Appmediateksoftware_development_kit---
OSopenwrtopenwrt23.05--

Explore more