Out of Bounds Write Vulnerability in MediaTek Modem Products
CVE-2026-20520

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20520?

In MediaTek Modem, an out of bounds write vulnerability exists due to a lack of adequate bounds checking. This vulnerability can be exploited remotely if a User Equipment (UE) connects to a malicious base station operated by an attacker, enabling them to escalate privileges without requiring additional execution permissions. Notably, user interaction is not necessary for exploitation to occur.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.