CVE-2026-20465: an over-the-air out-of-bounds write in MediaTek's wlan AP driver
A heap-based out-of-bounds write in the wlan AP driver on MediaTek's MT6890, MT7915, MT7916, MT7981, and MT7986 chipsets.
We discovered a heap-based out-of-bounds write in a wlan AP driver shipped on several MediaTek chipsets — MT6890, MT7915, MT7916, MT7981, and MT7986. The driver is missing a bounds check on a specific IE field in AP mode, and a write past the allocated buffer opens the door to privilege escalation.
MediaTek assigned it a CVSS 3.1 score of 8.1 (AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N): the attack vector is adjacent network (understood as a device within range of the Wi-Fi radio), and triggering it needs no prior privileges and no user interaction. A full technical write-up will be provided soon.
References
dukpt (2026). "CVE-2026-20465: an over-the-air out-of-bounds write in MediaTek's wlan AP driver". newt lab research. https://newt-lab.com/en/research/cve-2026-20465-mediatek-wlan/