CVE-2026-20407 is a critical escalation of privilege vulnerability in MediaTek's WLAN STA driver, affecting multiple chipsets including mt7902, mt7920, and mt7921, among others. This flaw, stemming from a missing bounds check, allows for local privilege escalation without user interaction, requiring only user execution privileges. With a CVSS score of 9.3 (Critical), it poses a significant risk due to its low attack complexity and high impact on confidentiality, integrity, and availability. While no public exploits, Metasploit modules, or community discussions have been observed, organizations should prioritize patching given the severity and ease of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8CPE matchmatch criteria | cpe:2.3:a:mediatek:nbiot_sdk:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.3 Mastodon, and 1.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.