CVE-2026-20452 is a heap-based buffer overflow in a MediaTek WLAN AP driver. The flaw can corrupt memory and may enable remote code execution by a proximal or adjacent attacker. Exploitation requires user execution privileges and does not require user interaction.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept for CVE-2026-20452, a heap-based buffer overflow in the MediaTek WLAN Access Point driver. The repo contains three files: a README with vulnerability details and usage instructions, a single executable script (exploit.py), and a minimal requirements.txt listing scapy. There is no framework integration, no auxiliary modules, and no detection-only logic. The exploit's core capability is wireless frame injection. The script uses scapy to craft 802.11 QoS Data frames addressed to a target AP BSSID and embeds malformed Information Elements intended to trigger heap corruption in vulnerable MediaTek AP-mode drivers. It supports four variants: a single oversized vendor-specific IE, chained vendor IEs, an oversized HT Capabilities IE, and an oversized Extended Capabilities IE. The operator can tune overflow size, variant, frame count, and inter-frame delay. Operationally, the script validates the supplied BSSID and attacker MAC, constructs the malicious frame in craft_overflow_frame(), and repeatedly transmits it with sendp() over a monitor-mode interface. The expected outcome is denial of service or crash behavior on the target AP, as indicated by the script's own guidance to monitor for kernel oops or crashes via dmesg. No reverse shell, command execution, beaconing, or C2 behavior is present. Fingerprintable artifacts are limited to documentation URLs, example MAC addresses, example wireless interface names, and the local dmesg command reference. The actual target endpoint is not an IP or web service but a nearby Wi-Fi access point identified by BSSID, making this a wireless/adjacent-network exploit rather than a traditional network exploit.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.