Modem Denial of Service Vulnerability in MediaTek Products
CVE-2026-20503
Currently unrated
What is CVE-2026-20503?
A vulnerability exists in the MediaTek modem, resulting from a missing bounds check that can lead to a system crash. If a user equipment (UE) connects to a compromised base station controlled by an attacker, it enables the potential for remote denial of service without requiring any user interaction. The issue is documented with Patch ID MOLY01371002 and Issue ID MSV-9020.
Affected Version(s)
MediaTek chipset MT2716
MediaTek chipset MT2735
MediaTek chipset MT2737
