Mediatek
Mediatek IOT Yocto: vulnerabilities and CVEs
Mediatek IOT Yocto has 24 published vulnerabilities, 1 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs24
Last 12 months1
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20721 | High (7.8) | 0.09% | — | Oct 14, 2025 | In imgsensor, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2024-20100 | Critical (9.8) | 0.33% | — | Oct 7, 2024 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2024-20055 | Medium (6.3) | 0.08% | — | Apr 1, 2024 | In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation… |
| CVE-2023-32829 | Medium (6.7) | 0.09% | — | Oct 2, 2023 | In apusys, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2023-32828 | Medium (6.7) | 0.09% | — | Oct 2, 2023 | In vpu, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2023-32820 | High (7.5) | 0.41% | — | Oct 2, 2023 | In wlan firmware, there is a possible firmware assertion due to improper input handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for… |
| CVE-2023-32811 | Medium (6.7) | 0.10% | — | Sep 4, 2023 | In connectivity system driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not… |
| CVE-2023-32807 | Medium (4.4) | 0.10% | — | Sep 4, 2023 | In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-32806 | Medium (6.7) | 0.10% | — | Sep 4, 2023 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-20850 | Medium (6.5) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20849 | Medium (6.5) | 0.11% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible use after free due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20848 | Medium (6.5) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20847 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local denial of service with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20846 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20845 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20844 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20843 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20842 | Medium (6.5) | 0.10% | — | Sep 4, 2023 | In imgsys_cmdq, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20841 | Medium (6.5) | 0.10% | — | Sep 4, 2023 | In imgsys, there is a possible out of bounds write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20840 | Medium (6.5) | 0.10% | — | Sep 4, 2023 | In imgsys, there is a possible out of bounds read and write due to a missing valid range checking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20839 | Medium (4.2) | 0.10% | — | Sep 4, 2023 | In imgsys, there is a possible out of bounds read due to a missing valid range checking. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for… |
| CVE-2023-20835 | Medium (6.4) | 0.07% | — | Sep 4, 2023 | In camsys, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:… |
| CVE-2023-20812 | Medium (4.4) | 0.09% | — | Aug 7, 2023 | In wlan driver, there is a possible out of bounds write due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for… |
| CVE-2023-20673 | Medium (6.7) | 0.10% | — | May 15, 2023 | In vcu, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID:… |