Description
In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01811421; Issue ID: MSV-6788.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper validation of external input in the MediaTek, Inc. chipsets (CWE‑288). This flaw allows an attacker to inadvertently glean information from the device, enabling remote data disclosure. The flaw does not require execution privileges or user interaction, and the impact is limited to confidentiality breach.

Affected Systems

MediaTek, Inc. chipsets that include the Modem are not disclosed, so any device using the vulnerable Modem functionality is potentially at risk.

Risk and Exploitability

The likely attack vector is that an attacker can establish a base‑station link to the victim device without requiring privileged access or user interaction. The attack requires only that the device connect to a malicious base station. The low EPSS score (< 1 %) probability of exploitation in the wild, yet the relative ease of triggering and the confidentiality impact warrant vigilance. The CVSS score of 5.3 reflects a moderate impact on confidentiality, and the vulnerability is not currently in the CISA KEV catalog.

Generated by OpenCVE AI on July 15, 2026 at 22:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the MediaTek firmware patch identified by MOLY01811421.
  • Configure the network or device to reject connections from unauthorized or rogue base stations.
  • Monitor device logs for indications of rogue base station activity or attempts to trigger the vulnerability.

Generated by OpenCVE AI on July 15, 2026 at 22:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Improper Modem Input Validation

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in MediaTek Modem Enables Remote Information Disclosure

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in MediaTek Modem Enables Remote Information Disclosure

Sat, 11 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Leading to Remote Information Disclosure

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Leading to Remote Information Disclosure

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Information Disclosure via Rogue Base Station

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Information Disclosure via Rogue Base Station

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Enables Remote Information Disclosure

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Enables Remote Information Disclosure

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Modem Remote Information Disclosure via Rogue Base Station

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Modem Remote Information Disclosure via Rogue Base Station

Fri, 03 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Remote Information Disclosure via Rogue Base Station

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Firmware Remote Information Disclosure via Rogue Base Station

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Improper Input Validation in MediaTek Modem Firmware

Thu, 02 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Improper Input Validation in MediaTek Modem Firmware

Thu, 02 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Remote Information Disclosure via Improper Input Validation

Thu, 02 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Remote Information Disclosure via Improper Input Validation

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Enables Remote Information Disclosure in MediaTek Modem

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Improper Input Validation Enables Remote Information Disclosure in MediaTek Modem

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Leading to Remote Information Disclosure

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Improper Input Validation Leading to Remote Information Disclosure

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01811421; Issue ID: MSV-6788.
Weaknesses CWE-288
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-01T10:39:34.250Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20460

cve-icon Vulnrichment

Updated: 2026-07-01T10:37:12.253Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:00:17Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel