CVE-2026-20491

EUVD-2026-52081
In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10981478 (Note: For MT6890, MT6990, MT6988) / AUTO00851173 (Note: For MT2735, MT2737); Issue ID: MSV-7652.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 1.05%
Affected Products (NVD)
VendorProductVersion
mediatekmt2735_firmware
-
mediatekmt2737_firmware
-
mediatekmt6890_firmware
-
mediatekmt6988_firmware
-
mediatekmt6990_firmware
-
𝑥
= Vulnerable software versions