Remote Denial of Service Vulnerability in MediaTek Modem
CVE-2026-20504
Currently unrated
What is CVE-2026-20504?
In MediaTek Modem, a vulnerability exists that can result in a system crash due to an inadequate bounds check. An attacker could exploit this flaw by connecting a user equipment (UE) to a rogue base station under their control. Importantly, the attack does not require any execution privileges or user interaction, making it particularly concerning for affected users. A patch is available under Patch ID: MOLY00755024, addressing Issue ID: MSV-7865.
Affected Version(s)
MediaTek chipset MT2735
MediaTek chipset MT6833
MediaTek chipset MT6853
