CVE-2026-20407: Critical severity MediaTek Nbiot Sdk vulnerability
In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00464377; Issue ID: MSV-4905.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20407?
The severity of CVE-2026-20407 is classified as a medium risk due to the potential for local escalation of privilege.
How do I fix CVE-2026-20407?
To fix CVE-2026-20407, apply the patch with ID WCNCR00464377 provided by MediaTek.
What type of attack can result from exploiting CVE-2026-20407?
Exploiting CVE-2026-20407 can lead to a local escalation of privilege, allowing users to gain unauthorized access to elevated rights.
Is user interaction required for CVE-2026-20407 exploitation?
No, user interaction is not needed for the exploitation of CVE-2026-20407.
Which software versions are affected by CVE-2026-20407?
CVE-2026-20407 affects MediaTek NBIOT SDK versions up to and including 3.8.