Description
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01816800; Issue ID: MSV-6842.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a CWE-288 problem caused by improper input validation in the Modem firmware of MediaTek chipsets, which allows malformed data from a connected user equipment to trigger a crash. This crash results in a remote denial of service, interrupting normal device operation. The weakness conforms to the denial‑of‑service condition described by CWE-288.

Affected Systems

All MediaTek chipset devices that include the vulnerable Modem firmware; so any device running the unpatched firmware could be affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity impact. Exploitation requires the attacker to operate a rogue base station that transmits crafted data to the device. The vulnerability is limited to connections over the radio interface used by the modem, without the need for further system access. The EPSS score indicates a very low exploitation probability, less than 1%.

Generated by OpenCVE AI on August 1, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware patch identified as MOLY01816800 to all devices suspected of running the vulnerable firmware.
  • Configure the device to reject registration or data transmission from unknown or untrusted base stations as a temporary protective measure.
  • Continuously monitor device logs for unexpected crashes or radio interface failures to detect potential exploitation attempts.

Generated by OpenCVE AI on August 1, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Enables Remote Denial of Service

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in MediaTek Modem Enables Remote Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in MediaTek Modem Enables Remote Denial of Service

Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in MediaTek Modem

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in MediaTek Modem

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Modem Input Validation

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Modem Input Validation

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Denial of Service via Improper Input Validation

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Denial of Service via Improper Input Validation

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash via Improper Input Validation Leading to Remote DoS

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Crash via Improper Input Validation Leading to Remote DoS

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Covert Modem Firmware Crash Causing Remote Denial of Service

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Covert Modem Firmware Crash Causing Remote Denial of Service

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Modem Crash from Improper Input Validation Leading to Remote Denial of Service

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Modem Crash from Improper Input Validation Leading to Remote Denial of Service

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Modem input validation flaw can crash device, enabling remote denial of service

Sun, 05 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Modem input validation flaw can crash device, enabling remote denial of service

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Causing Remote Denial of Service on MediaTek Chipsets

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Causing Remote Denial of Service on MediaTek Chipsets

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in MediaTek Modem

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Denial of Service via Improper Input Validation in MediaTek Modem

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Modem Component Input Validation Failure Leads to Remote Denial of Service on MediaTek Chipsets

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Modem Component Input Validation Failure Leads to Remote Denial of Service on MediaTek Chipsets

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Allowing Remote Denial of Service on MediaTek Chipsets

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Modem Input Validation Crash Allowing Remote Denial of Service on MediaTek Chipsets

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Modem Denial of Service via Improper Input Validation on MediaTek Chipset

Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Modem Denial of Service via Improper Input Validation on MediaTek Chipset

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01816800; Issue ID: MSV-6842.
Weaknesses CWE-288
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-01T10:39:19.025Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20459

cve-icon Vulnrichment

Updated: 2026-07-01T10:37:55.959Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:00:14Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel