In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
History

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt6833
Mediatek mt6833 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6873
Mediatek mt6873 Firmware
Mediatek mt6875
Mediatek mt6875 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6891
Mediatek mt6891 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt8675
Mediatek mt8675 Firmware
Mediatek mt8771
Mediatek mt8771 Firmware
Mediatek mt8791
Mediatek mt8791 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8797
Mediatek mt8797 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6833_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6853_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6873_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6875_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6877_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6883_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6885_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6889_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6891_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6893_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8675_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8771_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791t_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8797_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt6833
Mediatek mt6833 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6873
Mediatek mt6873 Firmware
Mediatek mt6875
Mediatek mt6875 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6891
Mediatek mt6891 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt8675
Mediatek mt8675 Firmware
Mediatek mt8771
Mediatek mt8771 Firmware
Mediatek mt8791
Mediatek mt8791 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8797
Mediatek mt8797 Firmware

Mon, 07 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Modem Bounds Check Omission Causing Remote Denial of Service on MediaTek Chipsets

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 07 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Weaknesses CWE-617
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2026-09-07T01:57:18.937Z

Updated: 2026-09-07T10:36:49.120Z

Reserved: 2025-11-03T01:30:59.028Z

Link: CVE-2026-20504

cve-icon Vulnrichment

Updated: 2026-09-07T10:36:43.282Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T02:17:19.143

Modified: 2026-09-09T02:55:33.787

Link: CVE-2026-20504

cve-icon Redhat

No data.