MediaTek, Inc.

First CVE: Jan 4, 2022Active for: 5 years
967
CVEs Published
More CVEs Published than 91% of tracked CNAs
193.4
Avg CVEs / Year
More Avg CVEs / Year than 94% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by MediaTek, Inc. as a CNA, 98.9% affect products that MediaTek, Inc. develops as a vendor.

98.9%
Self-reported: 956Third-party: 11

Of all the CVEs published that affect products developed by MediaTek, Inc., 92.1% are self-published by MediaTek, Inc. as a CNA.

92.1%
Self-published: 956Published by other CNAs: 82

Trends Over Time

The number and severity of CVEs published by MediaTek, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2022
4 years ago
Most Recent CVE
Jul 1, 2026
23 days ago

Top CVEs

All CVEs published by MediaTek, Inc. as a CNA, regardless of affected vendor or product.

967 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed.
Mar 4, 20249.859NONO
In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to rem
Aug 4, 20258.838NONO
In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional
Aug 4, 20258.837NONO
In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution priv
Aug 4, 20258.835NONO
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station cont
Jul 1, 20267.534NONO
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges
Jun 1, 20268.034NONO
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the Sy
Jul 1, 20266.732NONO
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the
Jun 1, 20267.832NONO
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD)
Jul 6, 20229.832NONO
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additiona
Jul 6, 20229.832NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA967 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local749 (77.5%)
Network140 (14.5%)
Unknown0 (0.0%)
Physical32 (3.3%)
Adjacent Network46 (4.8%)
Attack Complexity
Low871 (90.1%)
High96 (9.9%)
Unknown0 (0.0%)
User Interaction
None911 (94.2%)
Unknown0 (0.0%)
Required56 (5.8%)
Privileges Required
Low151 (15.6%)
High621 (64.2%)
None195 (20.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (967 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by MediaTek, Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by MediaTek, Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs