MediaTek's vulnerability footprint spans a heavily represented portfolio of mobile and embedded system-on-chip (SoC) designs, including the widely deployed MT6885, MT6877, MT6893, MT6853, and MT6833 processor families, which ship across billions of consumer and enterprise devices. The vendor's disclosures concentrate on memory-safety and input-handling weaknesses—out-of-bounds reads and writes, use-after-free conditions, integer overflows, and improper input validation—that are characteristic of large, performance-sensitive firmware codebases and reflect the complexity of multimedia and wireless subsystems. Because MediaTek SoCs anchor device-wide security and are difficult to patch once shipped, these vulnerability classes carry outsized impact despite their distribution across multiple chipsets and manufacturers. Defenders should track this vendor's security notices closely, inventory affected device firmware by chipset, and prioritize firmware updates where available; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by MediaTek, Inc. over time
Of all the CVEs published by MediaTek, Inc. as a CNA, 98.9% affect products that MediaTek, Inc. develops as a vendor.
Of all the CVEs published that affect products developed by MediaTek, Inc., 92.1% are self-published by MediaTek, Inc. as a CNA.
Signals from CVEs in this vendor scope (1038 CVEs).
1,038 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-20017CRITICAL In wlan service, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. | Mar 4, 2024 | 9.8 | 59 | NO | NO |
CVE-2026-20452HIGH In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges | Jun 1, 2026 | 8.0 | 34 | NO | NO |
CVE-2026-20455HIGH In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the | Jun 1, 2026 | 7.8 | 32 | NO | NO |
CVE-2022-21744CRITICAL In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) | Jul 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-20083CRITICAL In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additiona | Jul 6, 2022 | 9.8 | 32 | NO | NO |
CVE-2026-20418CRITICAL In Thread, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privileges needed. | Feb 2, 2026 | 9.8 | 31 | NO | NO |
CVE-2021-31574CRITICAL In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additi | Feb 6, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-30636CRITICAL In MediaTek LinkIt SDK before 4.6.1, there is a possible memory corruption due to an integer overflow during mishandled memory allocation by pvPortCalloc and pvPortRealloc. | Jan 24, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-20433HIGH In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station co | Apr 7, 2026 | 8.8 | 30 | NO | NO |
CVE-2026-20430HIGH In wlan AP FW, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional ex | Mar 2, 2026 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1038 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by MediaTek, Inc..
Media articles that mention a CVE ID that affects a product developed by MediaTek, Inc. — matched by CVE ID, not by vendor name.