mediatek has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 5.5 (medium). None have a confirmed exploitation report. Most affected products: mt2716_firmware (2), mt2718_firmware (2), mt2735_firmware (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.5
- Publish → KEV
- —
- Last 90 days
- 5 prev 0
Products
- mt2716_firmware 2
- mt2718_firmware 2
- mt2735_firmware 1
Worst active — by depth score
CVE-2026-20502High· 8.4In vdec, there is a possible out of bounds write due to a missing bounds check46CVE-2026-20501High· 8.4In vdec, there is a possible out of bounds write due to a heap buffer overflow46CVE-2026-20500Medium· 5.5In Modem, there is a possible system crash due to improper input validation30CVE-2026-20504Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check29CVE-2026-20503Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check29
mediatek vulnerabilities
CVEs affecting mediatek, newest first. Open any entry for full detail, references, and exploit status.
5 CVEsRSS
CVE-2026-20504Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
CVE-2026-20503Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
CVE-2026-20502High· 8.4In vdec, there is a possible out of bounds write due to a missing bounds check
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
CVE-2026-20501High· 8.4In vdec, there is a possible out of bounds write due to a heap buffer overflow
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
CVE-2026-20500Medium· 5.5In Modem, there is a possible system crash due to improper input validation
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID:…