Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-20471

CVE-2026-20471: MediaTek DA Denial of Service Vulnerability

CVE-2026-20471 is a denial of service flaw in MediaTek DA component caused by an out of bounds write. Attackers with physical access can trigger local DoS. This article covers technical details, affected chipsets, and patches.

Published:

CVE-2026-20471 Overview

CVE-2026-20471 is an out-of-bounds write vulnerability in the MediaTek Download Agent (DA) component. The flaw stems from a missing bounds check that allows writes beyond an allocated buffer [CWE-787]. An attacker with physical access to the device can trigger the condition to cause a local denial of service. Exploitation requires no user interaction and no additional execution privileges. MediaTek addressed the issue in Patch ID ALPS10991588 for chipsets MT6880, MT6890, MT6990, MT6988, MT6986, and MT6813, and Patch ID AUTO00851171 for chipsets MT2735 and MT2737. The vendor tracks the issue internally as MSV-7790.

Critical Impact

An attacker with physical device access can trigger an out-of-bounds write in the MediaTek DA component, resulting in local denial of service without authentication or user interaction.

Affected Products

  • MediaTek chipsets MT6880, MT6890, MT6990, MT6988, MT6986, MT6813 (fixed via ALPS10991588)
  • MediaTek chipsets MT2735, MT2737 (fixed via AUTO00851171)
  • Devices running the affected Download Agent (DA) firmware component

Discovery Timeline

  • 2026-08-03 - CVE-2026-20471 published to NVD
  • 2026-08-03 - Last updated in NVD database

Technical Details for CVE-2026-20471

Vulnerability Analysis

The vulnerability resides in the MediaTek Download Agent (DA), a boot-stage component used during firmware flashing and device provisioning. The DA processes structured input during low-level device communication over USB. A missing bounds check on incoming data allows the component to write beyond the end of a fixed-size buffer. The out-of-bounds write corrupts adjacent memory, causing the DA process to fault and terminate. This condition results in a local denial of service against the flashing or boot workflow. Impact is limited to availability, with no confidentiality or integrity compromise reported by the vendor.

Root Cause

The root cause is a classic out-of-bounds write [CWE-787]. The DA code path accepts a length or offset value from an attacker-controlled input stream and uses it directly in a memory write operation. The code lacks a validation step to confirm that the write destination and length remain within the bounds of the target buffer. When the supplied values exceed the buffer size, the write corrupts adjacent stack or heap memory, producing an abort.

Attack Vector

Exploitation requires physical access to the target device. An attacker connects to the device through the interface exposed by the Download Agent, typically USB during boot or recovery mode. The attacker then submits crafted input that triggers the unchecked write path. No credentials, user interaction, or elevated privileges are required. The condition produces a denial of service against the DA service; the device or flashing session becomes unavailable until reset. The requirement for physical access substantially limits the attack surface to scenarios such as supply chain interception, lost or stolen devices, and repair or service environments.

Refer to the MediaTek Security Bulletin August 2026 for vendor-supplied technical details.

Detection Methods for CVE-2026-20471

Indicators of Compromise

  • Unexpected DA process crashes or aborts during firmware flashing or device provisioning sessions.
  • Boot or recovery logs showing repeated failures traceable to the Download Agent component.
  • Physical connections to device USB or JTAG interfaces on production or fielded units outside of authorized service workflows.

Detection Strategies

  • Monitor factory, repair, and service workflows for anomalous DA session terminations or repeated flash failures.
  • Review boot loader and DA logs on affected MediaTek chipsets for crash signatures aligned with out-of-bounds write faults.
  • Track device inventory for units that have been physically accessed by unauthorized personnel or spent time outside supply chain custody.

Monitoring Recommendations

  • Enforce chain-of-custody logging for devices during manufacturing, transit, and repair to correlate physical access events with device faults.
  • Alert on multiple DA failures against the same device or batch, which may indicate iterative exploitation attempts.
  • Include the MediaTek Patch IDs ALPS10991588 and AUTO00851171 in firmware inventory audits to confirm patch state across fleets.

How to Mitigate CVE-2026-20471

Immediate Actions Required

  • Apply the MediaTek patches identified as ALPS10991588 (MT6880, MT6890, MT6990, MT6988, MT6986, MT6813) and AUTO00851171 (MT2735, MT2737) through the device OEM update channel.
  • Verify firmware build strings on affected devices to confirm the patched Download Agent component is deployed.
  • Restrict physical access to devices in manufacturing, staging, and repair environments.

Patch Information

MediaTek released fixes as documented in the MediaTek Security Bulletin August 2026. The vendor references Issue ID MSV-7790 and Patch IDs ALPS10991588 and AUTO00851171. Device manufacturers integrate these patches into OEM firmware releases; end users should install OEM-provided updates covering the August 2026 MediaTek security level.

Workarounds

  • Physically secure devices to prevent unauthorized USB or debug interface access, since exploitation requires physical connection.
  • Disable or lock down bootloader and download modes on production devices where the OEM firmware permits such controls.
  • Enforce tamper-evident packaging and supply chain integrity checks for devices built on affected MediaTek chipsets until patched firmware is deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.