CVE-2026-20423Disclosure(mediatek / mt7902)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mediatek mt7902 systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00465314; Issue ID: MSV-4956.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-749CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mt7902
  • mt7920
  • mt7921
  • mt7922

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-03-02); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
mt7902mt7920mt7921mt7922mt7925mt7927nbiot_sdk

1 version affected across 7 products

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-03-02: 3Mentions · 2026-03-04: 2Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-03-07: 1Patch / Workaround · 2026-03-04: 1Technical Details · 2026-03-02: 3Technical Details · 2026-03-05: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 103-0203-0403-0503-0603-07
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-023
Disclosure3
2026-03-042
General1Patch1
2026-03-051
Disclosure1
2026-03-061
Disclosure1
2026-03-071
Disclosure1
Full discourse8 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20423 Local Privilege Escalation in WLAN STA Driver via Out-of-Bounds Write https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20423

    Post summary

    The text announces CVE-2026-20423, a local privilege escalation vulnerability in the WLAN STA driver caused by an out‑of‑bounds write, without providing details on exploitation, mitigation, or PoC.

    0000154
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-20423 In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privil… https://www.cve.org/CVERecord?id=CVE-2026-20423

    Post summary

    The post discloses a local privilege escalation vulnerability in the wlan STA driver caused by an out‑of‑bounds write, without mentioning any PoC, exploit, or patch.

    00010512
    56.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-20423 (CVSS:7.8, HIGH) is Modified. In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca..https://nvd.nist.gov/vuln/detail/CVE-2026-20423 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    CVE‑2026‑20423 is a high‑severity vulnerability involving an out‑of‑bounds write in the WLAN STA driver that could lead to local privilege escalation.

    0000022
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-20423 (CVSS:7.8, HIGH) is Modified. In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca..https://nvd.nist.gov/vuln/detail/CVE-2026-20423 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-20423 as a high‑severity out‑of‑bounds write flaw in the wlan STA driver, providing technical details but no PoC, exploit, or patch information.

    0000021
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-20423 (CVSS:7.8, HIGH) is Modified. In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local esca..https://nvd.nist.gov/vuln/detail/CVE-2026-20423 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces that CVE-2026-20423 is a HIGH‑severity WLAN driver vulnerability, noting it is modified, but offers no evidence of exploitation, PoC, or patch.

    0000027
    173 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos MediaTek ❗ CVE-2026-20434 ❗ CVE-2026-20430 ❗ CVE-2026-20423 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mediatek-6/ https://t.co/e3SFoQSKMx

    Post summary

    The post lists three MediaTek CVEs and includes links to external resources, but lacks detailed technical information, PoC, exploit code, or patch discussion.

    00000102
    6.6K followersView on X
  • EarlyNarratives Cybersecurity@earlyn_cyber
    Patch

    MediaTek March updates (cyber). Summary: Classification: Severe, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.1: None, CVEs: CVE-2026-20423, https://cybersecurity.earlynarratives.com/s/45ac5dbe-0114-4155-a3ed-dcc7857d2689/7tV6SP8MSRgaJM0wms3wZE89QhVU9JRW

    Post summary

    MediaTek has released an official fix for CVE-2026-20423, classified as severe, but the post provides no exploit details or evidence of active exploitation.

    0000040
    2 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-20423 In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privil… https://www.cve.org/CVERecord?id=CVE-2026-20423 ----- Traducción: CVE-2026-20423 En … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑20423, describing an out‑of‑bounds write in the wlan STA driver that could allow local privilege escalation, but provides no PoC, exploit, or patch information.

    0000033
    55 followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
HWmediatekmt7902---
HWmediatekmt7920---
HWmediatekmt7921---
HWmediatekmt7922---
HWmediatekmt7925---
HWmediatekmt7927---
Appmediateknbiot_sdk---

Explore more