Description
In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
Published: 2026-07-01
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, this vulnerability is an unchecked memory write in the Modem component that can be triggered when a device receives data from a rogue base station. If adequately exploited, an attacker can corrupt memory and elevate privileges on the device, enabling privileged actions without extra execution rights. This is a classic buffer overflow (CWE-787) and does not require any user interaction.

Affected Systems

The flaw exists in MediaTek chipset Modem firmware. Specific the MOLY01402160 is applied. The patch can be obtained from the MediaTek reference provided.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity, and the EPSS score is < 1%, implying a low but non‑zero probability of exploitation. Because the attack can be launched over the air without user interaction and does not require additional privileges, an adversary controlling a rogue base station could leverage this vector. The vulnerability is not currently in CISA’s KEV catalog, but its nature demands urgent remediation.

Generated by OpenCVE AI on August 1, 2026 at 23:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware update that includes the MOLY01402160 patch.
  • Configure the modem or network controller to reject connections from untrusted base stations by enforcing strict MCC/MNC filtering or enabling network access control.
  • Monitor cellular traffic for signs of rogue base station activity, and isolate or investigate devices that connect to unknown networks.

Generated by OpenCVE AI on August 1, 2026 at 23:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Modem firmware buffer overflow exploitable by rogue base station

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Memory Corruption in MediaTek Modem Firmware

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Memory Corruption in MediaTek Modem Firmware

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Memory Corruption Enables Remote Privilege Escalation

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Memory Corruption Enables Remote Privilege Escalation

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Enables Remote Privilege Escalation

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Enables Remote Privilege Escalation

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Modem Memory Corruption on MediaTek Chipsets

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Privilege Escalation via Modem Memory Corruption on MediaTek Chipsets

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Missing Bounds Check Allows Remote Privilege Escalation

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Missing Bounds Check Allows Remote Privilege Escalation

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Buffer Overflow Enabling Remote Privilege Escalation

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Buffer Overflow Enabling Remote Privilege Escalation

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in MediaTek Modem Firmware Allows Remote Privilege Escalation

Wed, 01 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Vulnerability Allows Remote Privilege Escalation via Rogue Base Station

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Modem Leading to Remote Privilege Escalation

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Memory Corruption in Modem Leading to Remote Privilege Escalation

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.
Weaknesses CWE-787
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-02T03:55:19.970Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20458

cve-icon Vulnrichment

Updated: 2026-07-01T10:38:41.163Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:00:14Z

Weaknesses