System Crash Vulnerability in MediaTek Modem Affects User Equipment
CVE-2026-20525
Currently unrated
What is CVE-2026-20525?
The MediaTek modem has a vulnerability that allows for a potential system crash caused by improper input validation. This flaw can be exploited by an attacker to initiate a remote denial of service. If a User Equipment (UE) connects to a malicious base station controlled by the attacker, the device could become unresponsive without requiring any user interaction. It's crucial for users of affected MediaTek modems to ensure they implement the necessary patches to mitigate this risk.
Affected Version(s)
MediaTek chipset MT2716
MediaTek chipset MT6835
MediaTek chipset MT6858
