Mediatek
Mediatek Mt6988 Firmware: vulnerabilities and CVEs
Mediatek Mt6988 Firmware has 12 published vulnerabilities, 12 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs12
Last 12 months12
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20503 | Medium (5.3) | 0.19% | — | Sep 7, 2026 | In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional… |
| CVE-2026-20500 | Medium (5.5) | 0.09% | — | Sep 7, 2026 | In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID:… |
| CVE-2026-20494 | Medium (5.5) | 0.15% | — | Aug 3, 2026 | In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not… |
| CVE-2026-20493 | Medium (4.4) | 0.14% | — | Aug 3, 2026 | In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed… |
| CVE-2026-20492 | Medium (5.5) | 0.11% | — | Aug 3, 2026 | In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2026-20491 | Medium (5.5) | 0.15% | — | Aug 3, 2026 | In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch… |
| CVE-2026-20490 | Medium (4.4) | 0.14% | — | Aug 3, 2026 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service if a malicious actor has already obtained the System privilege. User interaction is not needed… |
| CVE-2026-20484 | Medium (4.4) | 0.16% | — | Aug 3, 2026 | In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is… |
| CVE-2026-20480 | Medium (5.5) | 0.14% | — | Aug 3, 2026 | In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2026-20478 | Medium (5.5) | 0.14% | — | Aug 3, 2026 | In Audio HAL, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2026-20476 | Medium (5.5) | 0.15% | — | Aug 3, 2026 | In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch ID:… |
| CVE-2026-20449 | Medium (6.5) | 0.22% | — | May 4, 2026 | In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional… |