CVE-2026-20534
Received Received - Intake

Out of Bounds Read in Modem Leading to Remote DoS

Vulnerability report for CVE-2026-20534, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: MediaTek, Inc.

Description

In Modem, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01797547; Issue ID: MSV-9155.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mediatek modem *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Modem is caused by an incorrect bounds check, leading to a possible out of bounds read. It allows remote denial of service if a user equipment (UE) connects to a rogue base station controlled by an attacker. No additional privileges or user interaction are required for exploitation.

Impact Analysis

If exploited, this vulnerability could cause your device to experience a denial of service, making it unable to function properly. This could disrupt services like calls, data, or internet access if your device connects to a malicious base station.

Compliance Impact

This vulnerability does not provide specific details about compliance impacts on standards like GDPR or HIPAA. The issue involves a possible out of bounds read in Modem leading to remote denial of service under specific conditions, but no direct implications for data protection or privacy regulations are mentioned.

Mitigation Strategies

Apply the provided patch with ID MOLY01797547 to address the incorrect bounds check issue. Ensure your Modem software is updated to the latest version to prevent potential remote denial of service attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20534. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart