In httpclient, there is a possible out of bounds write due to uninitialized data. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WSAP00103831; Issue ID: WSAP00103831.
Cite this page
CVE-2022-26437. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-26437
Use CWE-908, Mediatek vendor hub and Nbiot Sdk product page to widen CVE-2022-26437 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-20680, CVE-2026-20407 and CVE-2026-20423 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 6th, 2026.