Remote Denial of Service Vulnerability in MediaTek Modem
CVE-2026-20504

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
7 September 2026

What is CVE-2026-20504?

In MediaTek Modem, a vulnerability exists that can result in a system crash due to an inadequate bounds check. An attacker could exploit this flaw by connecting a user equipment (UE) to a rogue base station under their control. Importantly, the attack does not require any execution privileges or user interaction, making it particularly concerning for affected users. A patch is available under Patch ID: MOLY00755024, addressing Issue ID: MSV-7865.

Affected Version(s)

MediaTek chipset MT2735

MediaTek chipset MT6833

MediaTek chipset MT6853

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.