Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

MediaTek, Inc.

First CVE: Jun 8, 2018Active for: 8 yearsTotal CVEs: 1,038
12.5
VTI Score
Low

MediaTek's vulnerability footprint spans a heavily represented portfolio of mobile and embedded system-on-chip (SoC) designs, including the widely deployed MT6885, MT6877, MT6893, MT6853, and MT6833 processor families, which ship across billions of consumer and enterprise devices. The vendor's disclosures concentrate on memory-safety and input-handling weaknesses—out-of-bounds reads and writes, use-after-free conditions, integer overflows, and improper input validation—that are characteristic of large, performance-sensitive firmware codebases and reflect the complexity of multimedia and wireless subsystems. Because MediaTek SoCs anchor device-wide security and are difficult to patch once shipped, these vulnerability classes carry outsized impact despite their distribution across multiple chipsets and manufacturers. Defenders should track this vendor's security notices closely, inventory affected device firmware by chipset, and prioritize firmware updates where available; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
1,038
Total CVEs
More Total CVEs than 100% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 41% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by MediaTek, Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 8, 2018
8 years ago
Most Recent CVE
Jun 1, 2026
53 days ago

Self-Reporting Analysis

Of all the CVEs published by MediaTek, Inc. as a CNA, 98.9% affect products that MediaTek, Inc. develops as a vendor.

98.9%
Self-reported: 956 (98.9%)
Third-party: 11 (1.1%)

Of all the CVEs published that affect products developed by MediaTek, Inc., 92.1% are self-published by MediaTek, Inc. as a CNA.

92.1%
Self-published: 956 (92.1%)
Other CNAs: 82 (7.9%)

Products(582 total)

Top CVEs

Signals from CVEs in this vendor scope (1038 CVEs).

1,038 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-20017CRITICAL
In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed.
Mar 4, 20249.859NONO
CVE-2026-20452HIGH
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges
Jun 1, 20268.034NONO
CVE-2026-20455HIGH
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the
Jun 1, 20267.832NONO
CVE-2022-21744CRITICAL
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD)
Jul 6, 20229.832NONO
CVE-2022-20083CRITICAL
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additiona
Jul 6, 20229.832NONO
CVE-2026-20418CRITICAL
In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed.
Feb 2, 20269.831NONO
CVE-2021-31574CRITICAL
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additi
Feb 6, 20239.831NONO
CVE-2021-30636CRITICAL
In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc.
Jan 24, 20229.831NONO
CVE-2026-20433HIGH
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station co
Apr 7, 20268.830NONO
CVE-2026-20430HIGH
In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ex
Mar 2, 20268.830NONO
View all 1,038 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products1,038 CVEs
77%
19%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local795 (76.6%)
Network168 (16.2%)
Unknown0 (0.0%)
Physical32 (3.1%)
Adjacent Network43 (4.1%)
Attack Complexity
Low947 (91.2%)
High91 (8.8%)
Unknown0 (0.0%)
User Interaction
None972 (93.6%)
Unknown0 (0.0%)
Required66 (6.4%)
Privileges Required
Low169 (16.3%)
High651 (62.7%)
None218 (21.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (1038 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by MediaTek, Inc..

Media Mentions

Media articles that mention a CVE ID that affects a product developed by MediaTek, Inc. — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For MediaTek, Inc.'s Products

View all 4 CNAs →

Top CWEs