System Crash Vulnerability in MediaTek Modem Affects User Equipment
CVE-2026-20525

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20525?

The MediaTek modem has a vulnerability that allows for a potential system crash caused by improper input validation. This flaw can be exploited by an attacker to initiate a remote denial of service. If a User Equipment (UE) connects to a malicious base station controlled by the attacker, the device could become unresponsive without requiring any user interaction. It's crucial for users of affected MediaTek modems to ensure they implement the necessary patches to mitigate this risk.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT6835

MediaTek chipset MT6858

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.