Description
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in the modem, where improper input validation can cause a system crash. This corresponds to CWE-476, the null pointer dereference flaw. An attacker who can act as a rogue base station—if a user equipment connects to it—can trigger the crash, leading to a denial of service. No elevation of privileges or user interaction is required for exploitation, but the crash disrupts all services dependent on the modem.

Affected Systems

The affected component is the Modem firmware on MediaTek chipsets used in mobile devices. The exact firmware versions prior to the fix are not listed, but any build lacking the patch identified as MOLY01826924 (issue MSV-7301) is potentially vulnerable.

Risk and Exploitability

Exploitability is moderate, as an attacker can act as a rogue base station and send malformed data to the UE without any privileges or user interaction. The CVSS score of 5.3 indicates a moderate impact. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, so the likelihood of exploitation in the wild remains low, but the risk to affected devices remains significant.

Generated by OpenCVE AI on July 15, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware update identified as patch ID MOLY01826924 to the affected Modem firmware.
  • If a firmware update cannot be applied immediately, disable or restrict Modem services that allow unsolicited base station connections until a patch is available.
  • Continuously monitor the network for anomalous base station activity and consider blocking or flagging unknown cells until the vulnerability is resolved.

Generated by OpenCVE AI on July 15, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Modem Crash due to Improper Input Validation Can Cause Remote Denial of Service

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Modem Crash due to Improper Input Validation Can Cause Remote Denial of Service

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash Leads to Remote Denial of Service via Rogue Base Station

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash Leads to Remote Denial of Service via Rogue Base Station

Sat, 11 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Modem Input Validation Error on MediaTek Chipsets

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Modem Input Validation Error on MediaTek Chipsets

Thu, 09 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Leading to Remote Denial of Service

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Leading to Remote Denial of Service

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Crash Allowing Remote Denial of Service

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Crash Allowing Remote Denial of Service

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Improper Modem Input Validation Allows Remote Denial of Service

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Improper Modem Input Validation Allows Remote Denial of Service

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Modem Crash Due to Improper Input Validation on MediaTek Chipsets Enables Remote DoS

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Modem Crash Due to Improper Input Validation on MediaTek Chipsets Enables Remote DoS

Sat, 04 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Modem Crash Vulnerability Causes Remote Denial of Service via Rogue Base Station

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Modem Crash Vulnerability Causes Remote Denial of Service via Rogue Base Station

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash via Improper Input Validation Leading to Remote Denial of Service

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash via Improper Input Validation Leading to Remote Denial of Service

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MediaTek Modem Firmware Enables Remote Denial of Service

Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MediaTek Modem Firmware Enables Remote Denial of Service

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Modem Crash Enabling Remote Denial of Service via Improper Input Validation

Thu, 02 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Modem Crash Enabling Remote Denial of Service via Improper Input Validation

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Modem firmware crash due to improper input validation leading to remote denial of service

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Modem firmware crash due to improper input validation leading to remote denial of service

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01826924; Issue ID: MSV-7301.
Weaknesses CWE-476
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-01T10:40:26.558Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20457

cve-icon Vulnrichment

Updated: 2026-07-01T10:40:23.313Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:00:17Z

Weaknesses