SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-20471

MEDIUM · CVSS 4.6 EPSS 0.17% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

The vulnerability arises from a missing bounds check in the DA component, allowing for an out-of-bounds write that could lead to a local denial of service if an attacker has physical access to the affected device. Exploitation does not require additional execution privileges or user interaction, making it a significant risk for devices utilizing the specified chipsets. Manufacturers and organizations using these chipsets should prioritize applying the provided patches to mitigate potential disruptions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-20471
Severity
MEDIUM
CVSS
4.6
EPSS
0.17%

Original NVD Description

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS10991588 (Note: For MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) / AUTO00851171 (Note: For MT2735, MT2737); Issue ID: MSV-7790.