Description
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability is an unchecked memory write in the Modem component that can be triggered when a device receives data from a rogue base station. If adequately exploited, an attacker can corrupt memory and elevate privileges on the device, enabling privileged actions without extra execution rights. This is a classic buffer overflow (CWE-787) and does not require any user interaction.

Affected Systems

The flaw exists in MediaTek chipset Modem firmware. Specific affected firmware versions are not listed, so any device running Mediatek Modem software prior to the release of patch MOLY01402160 remains vulnerable. The patch can be obtained from the MediaTek reference provided

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, and the EPSS score is < 1%, implying a low but non‑zero probability of exploit. Based on the description, an attacker that can control a rogue base station can trigger the memory corruption without user interaction, enabling privilege escalation on the device. Because the attack can be launched over the air without user interaction and does not require additional privileges, an adversary controlling a rogue base station could leverage this vector. The vulnerability is not currently in CISA’s KEV catalog, but its nature demands urgent remediation.

Generated by OpenCVE AI on July 15, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware patch (MOLY01402160) released by the vendor
  • Update the device to the latest approved Mediatek firmware version to ensure the patch is applied
  • Restrict or monitor connections to non‑trusted base stations, and enable network access controls to detect and prevent rogue network activity

Generated by OpenCVE AI on July 15, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Memory Corruption in MediaTek Modem Firmware

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Memory Corruption Enables Remote Privilege Escalation

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Memory Corruption Enables Remote Privilege Escalation

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Enables Remote Privilege Escalation

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Enables Remote Privilege Escalation

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Modem Memory Corruption on MediaTek Chipsets

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Modem Memory Corruption on MediaTek Chipsets

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Missing Bounds Check Allows Remote Privilege Escalation

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Missing Bounds Check Allows Remote Privilege Escalation

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Buffer Overflow Enabling Remote Privilege Escalation

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Buffer Overflow Enabling Remote Privilege Escalation

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Wed, 01 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Modem Leading to Remote Privilege Escalation

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Modem Leading to Remote Privilege Escalation

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
Weaknesses CWE-787
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-02T03:55:19.970Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20458

cve-icon Vulnrichment

Updated: 2026-07-01T10:38:41.163Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T10:30:05Z

Weaknesses