📦 Rdk B

by Rdkcentral

🔍 What is Rdk B?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-20080

CRITICAL CVSS 9.8 Jul 1, 2024

This vulnerability in MediaTek's GNSS service allows remote attackers to escalate privileges without user interaction due to improper certificate validation. It affects devices using MediaTek chipsets...

CVE-2024-20104

HIGH CVSS 8.4 Nov 4, 2024

This vulnerability in MediaTek's da component allows local attackers to write beyond allocated memory boundaries, potentially gaining elevated privileges on affected devices. It affects Android device...

CVE-2024-20089

HIGH CVSS 7.5 Sep 2, 2024

This vulnerability in MediaTek Wi-Fi drivers allows remote attackers to cause denial of service without authentication or user interaction. It affects devices using MediaTek chipsets with vulnerable w...

CVE-2024-20053

HIGH CVSS 8.4 Apr 1, 2024

This vulnerability in MediaTek's flashc component allows an attacker with system privileges to perform an out-of-bounds write due to an uncaught exception, leading to local privilege escalation. It af...

CVE-2025-20747

MEDIUM CVSS 6.7 Nov 4, 2025

This vulnerability in the GNSS service allows an out-of-bounds write due to incorrect bounds checking. It enables local privilege escalation if an attacker already has System privilege, requiring no u...

CVE-2025-20746

MEDIUM CVSS 6.7 Nov 4, 2025

This vulnerability in the GNSS service allows an attacker with System privilege to perform an out-of-bounds write, potentially leading to local privilege escalation. It affects devices using MediaTek ...

CVE-2025-20730

MEDIUM CVSS 6.7 Nov 4, 2025

This vulnerability allows local privilege escalation on MediaTek devices due to an insecure default value in the preloader component. An attacker with System privilege can exploit this to gain higher ...

CVE-2025-20722

MEDIUM CVSS 5.5 Oct 14, 2025

This CVE describes an integer overflow vulnerability in the GNSS driver that could lead to an out-of-bounds read. If exploited by a malicious actor with System privilege, it could result in local info...

CVE-2025-20696

MEDIUM CVSS 6.8 Aug 4, 2025

This CVE describes an out-of-bounds write vulnerability in DA (likely a MediaTek component) that could allow local privilege escalation. Attackers with physical access can exploit this without additio...

CVE-2025-20656

MEDIUM CVSS 6.8 Apr 7, 2025

This vulnerability in MediaTek DA software allows local attackers with physical access to escalate privileges through an out-of-bounds write. No user interaction or additional execution privileges are...

CVE-2025-20650

MEDIUM CVSS 6.8 Mar 3, 2025

This CVE describes an out-of-bounds write vulnerability in MediaTek's da component that could allow local privilege escalation. Attackers with physical access can exploit this without additional privi...

CVE-2024-20143

MEDIUM CVSS 6.6 Jan 6, 2025

This CVE describes an out-of-bounds write vulnerability in V6 DA (likely a MediaTek component) that allows local privilege escalation. Attackers with physical access can exploit this without additiona...

CVE-2024-20145

MEDIUM CVSS 6.6 Jan 6, 2025

This vulnerability in V6 DA allows local privilege escalation through an out-of-bounds write due to missing bounds checks. An attacker with physical access can exploit this without additional privileg...

CVE-2024-20136

MEDIUM CVSS 6.2 Dec 2, 2024

This vulnerability in MediaTek's da component allows local attackers to read memory beyond intended boundaries without requiring elevated privileges or user interaction. It affects devices using Media...

CVE-2024-20107

MEDIUM CVSS 6.2 Nov 4, 2024

CVE-2024-20107 is an out-of-bounds read vulnerability in MediaTek's da component that allows local attackers to read memory beyond allocated buffers without authentication or user interaction. This le...

CVE-2024-20085

MEDIUM CVSS 4.4 Sep 2, 2024

CVE-2024-20085 is an out-of-bounds read vulnerability in MediaTek power management components that could allow local information disclosure. Attackers with system execution privileges could read memor...

CVE-2023-32871

MEDIUM CVSS 5.3 May 6, 2024

This vulnerability in MediaTek's DA (Download Agent) allows local attackers to bypass permission checks due to an incorrect status verification. It enables local privilege escalation without requiring...

CVE-2024-20050

MEDIUM CVSS 4.4 Apr 1, 2024

This vulnerability in the flashc component allows local information disclosure when exploited by a process with System execution privileges. It affects MediaTek devices using vulnerable flashc firmwar...

CVE-2024-20052

MEDIUM CVSS 4.4 Apr 1, 2024

This vulnerability in MediaTek's flashc component allows local information disclosure when exploited by a process with System execution privileges. It affects MediaTek-powered devices and requires no ...