CVE-2026-20484
CVE-2026-20484 is a medium-severity vulnerability in Mediatek Mt8799 Firmware with a CVSS 3.x base score of 4.4. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-201.
Key facts
- Severity: Medium (CVSS 3.x base score 4.4)
- EPSS exploit prediction: 0% (2nd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-201
- Affected product: Mediatek Mt8799 Firmware
- Published:
- Last modified:
Description
In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
Frequently asked questions
- What is CVE-2026-20484?
- In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004.
- How severe is CVE-2026-20484?
- CVE-2026-20484 has a CVSS 3.x base score of 4.4, rated medium severity. It is exploitable over local access with low attack complexity, requires high privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2026-20484 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (2nd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2026-20484?
- CVE-2026-20484 primarily affects Mediatek Mt8799 Firmware. In total, 39 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2026-20484?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-20484 published?
- CVE-2026-20484 was published on 2026-08-03 and last updated on 2026-08-19.
References
Affected products (39)
- cpe:2.3:o:mediatek:mt8799_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6739_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6761_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6765_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6768_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6781_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6789_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6833_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6835_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6853_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6855_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6877_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6878_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6879_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6883_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6885_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6886_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6889_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6893_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6895_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6897_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6899_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6983_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6985_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6989_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6991_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt6993_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8171_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8188_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8189_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8390_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8391_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8668_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8676_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8678_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8696_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8792_firmware:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:mt8793_firmware:-:*:*:*:*:*:*:*
More vulnerabilities in Mediatek Mt8799 Firmware
- CVE-2026-20486 — Medium (CVSS 6.7): In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local…
- CVE-2026-20498 — Medium (CVSS 6.0): In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local…
- CVE-2026-20481 — Medium (CVSS 6.0): In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local…
- CVE-2026-20477 — Medium (CVSS 6.0): In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation…
- CVE-2026-20475 — Medium (CVSS 6.0): In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation…
- CVE-2026-20474 — Medium (CVSS 6.0): In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of…
All CVEs affecting Mediatek Mt8799 Firmware →
Other CWE-201 vulnerabilities
- CVE-2025-49408 — Critical (CVSS 10.0): Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded…
- CVE-2024-7205 — Critical (CVSS 9.4): When the device is shared, the homepage module are before 2.19.0 in eWeLink Cloud Service allows Secondary user to…
- CVE-2026-39912 — Critical (CVSS 9.1): V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the…
- CVE-2025-48749 — Critical (CVSS 9.1): Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive…
- CVE-2025-11500 — High (CVSS 8.7): Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication…
- CVE-2025-48045 — High (CVSS 8.7): An unauthenticated HTTP GET request to the /client.php endpoint will disclose the default administrator user…