MediaTek, Inc.
First CVE: Jan 4, 2022Active for: 5 years
967
CVEs Published
More CVEs Published than 91% of tracked CNAs
193.4
Avg CVEs / Year
More Avg CVEs / Year than 94% of tracked CNAs
6.5
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by MediaTek, Inc. as a CNA, 98.9% affect products that MediaTek, Inc. develops as a vendor.
98.9%
Self-reported: 956Third-party: 11
Of all the CVEs published that affect products developed by MediaTek, Inc., 92.1% are self-published by MediaTek, Inc. as a CNA.
92.1%
Self-published: 956Published by other CNAs: 82
Trends Over Time
The number and severity of CVEs published by MediaTek, Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 4, 2022
4 years ago
Most Recent CVE
Jul 1, 2026
23 days ago
Top CVEs
All CVEs published by MediaTek, Inc. as a CNA, regardless of affected vendor or product.
967 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20017CRITICAL In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. | Mar 4, 2024 | 9.8 | 59 | NO | NO |
CVE-2025-20700HIGH In the Airoha Bluetooth audio SDK, there is a possible permission bypass that allows access critical data of RACE protocol through Bluetooth LE GATT service. This could lead to rem | Aug 4, 2025 | 8.8 | 38 | NO | NO |
CVE-2025-20701HIGH In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional | Aug 4, 2025 | 8.8 | 37 | NO | NO |
CVE-2025-20702HIGH In the Airoha Bluetooth audio SDK, there is a possible unauthorized access to the RACE protocol. This could lead to remote escalation of privilege with no additional execution priv | Aug 4, 2025 | 8.8 | 35 | NO | NO |
CVE-2026-20458HIGH In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station cont | Jul 1, 2026 | 7.5 | 34 | NO | NO |
CVE-2026-20452HIGH In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges | Jun 1, 2026 | 8.0 | 34 | NO | NO |
CVE-2026-20463MEDIUM In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the Sy | Jul 1, 2026 | 6.7 | 32 | NO | NO |
CVE-2026-20455HIGH In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the | Jun 1, 2026 | 7.8 | 32 | NO | NO |
CVE-2022-21744CRITICAL In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) | Jul 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-20083CRITICAL In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additiona | Jul 6, 2022 | 9.8 | 32 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA967 CVEs
78%
18%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local749 (77.5%)
Network140 (14.5%)
Unknown0 (0.0%)
Physical32 (3.3%)
Adjacent Network46 (4.8%)
Attack Complexity
Low871 (90.1%)
High96 (9.9%)
Unknown0 (0.0%)
User Interaction
None911 (94.2%)
Unknown0 (0.0%)
Required56 (5.8%)
Privileges Required
Low151 (15.6%)
High621 (64.2%)
None195 (20.2%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (967 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by MediaTek, Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by MediaTek, Inc. as a CNA — matched by CVE ID, not by organization name.