Description
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248; Issue ID: MSV-4837.
Published: 2026-02-02
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper input validation flaw in MediaTek modem firmware that can cause the system to crash. Exploitation leads to a remote denial of service; the attacker does not need user interaction or elevated privileges. The weakness is classified as CWE-787, indicating a possible out-of-bounds write or similar memory corruption.

Affected Systems

The flaw affects MediaTek, Inc. media chipset devices that include the listed hardware models such as MT2735, MT2737, MT6813, MT6815, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6983, MT6985, MT6986, MT6989, MT6990, MT6991, MT6993, MT8668, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791t, MT8792, MT8793, MT8795t, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 and the NR5G platforms NR15 through NR17r. No specific firmware version ranges are provided, so all affected releases should be considered at risk until patched.

Risk and Exploitability

CVSS v3.1 score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit path is via a rogue base station that a user equipment (UE) connects to, requiring no user interaction or elevated privileges. Because the attacker can trigger a denial of service remotely, carriers and manufacturers should treat this as a moderate risk until the official patch is applied.

Generated by OpenCVE AI on April 16, 2026 at 07:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official firmware update identified by Patch ID MOLY01689248 to all affected MediaTek devices.
  • Deploy the latest firmware releases that incorporate the patch, ensuring that all modem firmware versions on the network are updated concurrently.
  • Configure network policy to detect and block connections to unauthenticated or rogue base stations, and enable logging of modem connection attempts for forensic analysis.

Generated by OpenCVE AI on April 16, 2026 at 07:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 07:30:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Failure Causing Remote Denial of Service

Tue, 17 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek nr15
Mediatek nr16
Mediatek nr17
Mediatek nr17r
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6813:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6815:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6858:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6896:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6993:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8668:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8755:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8793:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8795t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8863:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr17r:-:*:*:*:*:*:*:*
Vendors & Products Mediatek nr15
Mediatek nr16
Mediatek nr17
Mediatek nr17r

Wed, 04 Feb 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2737
Mediatek mt6813
Mediatek mt6815
Mediatek mt6833
Mediatek mt6835
Mediatek mt6853
Mediatek mt6855
Mediatek mt6858
Mediatek mt6873
Mediatek mt6875
Mediatek mt6877
Mediatek mt6878
Mediatek mt6879
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6886
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt6895
Mediatek mt6896
Mediatek mt6897
Mediatek mt6899
Mediatek mt6980
Mediatek mt6983
Mediatek mt6985
Mediatek mt6986
Mediatek mt6989
Mediatek mt6990
Mediatek mt6991
Mediatek mt6993
Mediatek mt8668
Mediatek mt8673
Mediatek mt8675
Mediatek mt8676
Mediatek mt8678
Mediatek mt8755
Mediatek mt8771
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8792
Mediatek mt8793
Mediatek mt8795t
Mediatek mt8797
Mediatek mt8798
Mediatek mt8863
Mediatek mt8873
Mediatek mt8883
Mediatek mt8893
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2737
Mediatek mt6813
Mediatek mt6815
Mediatek mt6833
Mediatek mt6835
Mediatek mt6853
Mediatek mt6855
Mediatek mt6858
Mediatek mt6873
Mediatek mt6875
Mediatek mt6877
Mediatek mt6878
Mediatek mt6879
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6886
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt6895
Mediatek mt6896
Mediatek mt6897
Mediatek mt6899
Mediatek mt6980
Mediatek mt6983
Mediatek mt6985
Mediatek mt6986
Mediatek mt6989
Mediatek mt6990
Mediatek mt6991
Mediatek mt6993
Mediatek mt8668
Mediatek mt8673
Mediatek mt8675
Mediatek mt8676
Mediatek mt8678
Mediatek mt8755
Mediatek mt8771
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8792
Mediatek mt8793
Mediatek mt8795t
Mediatek mt8797
Mediatek mt8798
Mediatek mt8863
Mediatek mt8873
Mediatek mt8883
Mediatek mt8893

Mon, 02 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 02 Feb 2026 08:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248; Issue ID: MSV-4837.
Weaknesses CWE-787
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-03-30T13:02:46.700Z

Reserved: 2025-11-03T01:30:59.007Z

Link: CVE-2026-20404

cve-icon Vulnrichment

Updated: 2026-02-02T21:14:21.136Z

cve-icon NVD

Status : Modified

Published: 2026-02-02T09:15:55.097

Modified: 2026-02-17T15:16:21.230

Link: CVE-2026-20404

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T07:15:28Z

Weaknesses