Out of Bounds Read Vulnerability in MediaTek Modem
CVE-2026-20541

Currently unrated

Key Information:

Vendor

MediaTek

Vendor
CVE Published:
5 October 2026

What is CVE-2026-20541?

A significant vulnerability exists in MediaTek Modem where a missing permission check may allow an out of bounds read. Attackers controlling a rogue base station can exploit this flaw, potentially leading to a remote denial of service. Importantly, no additional execution privileges are required, and user interaction is not necessary for the successful exploitation of this issue. Users are advised to update their firmware to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

MediaTek chipset MT2716

MediaTek chipset MT2735

MediaTek chipset MT2737

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.