Mediatek Mt8678 Firmware — known CVE vulnerabilities
Every CVE whose affected-product data names Mediatek Mt8678 Firmware, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (16)
CVE-2026-20433 — CVSS 8.8 (high): In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE…
CVE-2026-20432 — CVSS 8.0 (high): In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE…
CVE-2026-20451 — CVSS 6.7 (medium): In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious…
CVE-2026-20486 — CVSS 6.7 (medium): In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a…
CVE-2026-20431 — CVSS 6.5 (medium): In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a…
CVE-2026-20449 — CVSS 6.5 (medium): In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has…
CVE-2026-20450 — CVSS 6.5 (medium): In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has…
CVE-2025-20659 — CVSS 6.5 (medium): In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has…
CVE-2026-20474 — CVSS 6.0 (medium): In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a…
CVE-2026-20473 — CVSS 6.0 (medium): In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious…
CVE-2026-20475 — CVSS 6.0 (medium): In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a…
CVE-2026-20477 — CVSS 6.0 (medium): In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a…
CVE-2026-20484 — CVSS 4.4 (medium): In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a…
CVE-2026-20488 — CVSS 4.4 (medium): In display, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure if a…
CVE-2026-20489 — CVSS 4.4 (medium): In display, there is a possible information disclosure due to an integer overflow. This could lead to local information disclosure if a…
CVE-2026-20496 — CVSS 4.4 (medium): In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a…