Mediatek
Mediatek Nbiot SDK: vulnerabilidades y CVE
Mediatek Nbiot SDK tiene 9 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses4
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-20436 | Media (6.7) | 0.13% | — | 2 mar 2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User… |
| CVE-2026-20423 | Alta (7.8) | 0.13% | — | 2 mar 2026 | In wlan STA driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2026-20419 | Media (6.5) | 0.79% | — | 2 feb 2026 | In wlan AP/STA firmware, there is a possible system becoming irresponsive due to an uncaught exception. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed.… |
| CVE-2026-20407 | Crítica (9.3) | 0.18% | — | 2 feb 2026 | In wlan STA driver, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20687 | Media (5.5) | 0.17% | — | 8 jul 2025 | In Bluetooth driver, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20680 | Crítica (9.8) | 0.77% | — | 8 jul 2025 | In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for… |
| CVE-2025-20677 | Media (5.5) | 0.16% | — | 2 jun 2025 | In Bluetooth driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation.… |
| CVE-2025-20676 | Media (5.5) | 0.15% | — | 2 jun 2025 | In wlan STA driver, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with User execution privileges needed. User interaction is not needed for exploitation. Patch… |
| CVE-2022-26437 | Crítica (9.8) | 1.4% | — | 1 ago 2022 | In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for… |