Remote Denial of Service Vulnerability in MediaTek Modem
CVE-2026-20527

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20527?

A vulnerability in MediaTek's modem software may allow an attacker to cause a system crash due to a lack of proper bounds checking. If a user equipment (UE) connects to a rogue base station controlled by the attacker, this vulnerability could result in remote denial of service without requiring any additional execution privileges or user interaction. This vulnerability has been identified with Patch ID: MOLY01864925 and MOLY01210562, posing significant risks to device functionality.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.