Description
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267281 / MOLY01318201; Issue ID: MSV-6486.
Published: 2026-07-01
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing bounds check in the modem firmware permits an out‑of‑bounds write that can corrupt memory (CWE-787). No user interaction or elevated privileges are required for exploitation.

Affected Systems

MediaTek, Inc. chipsets are affected. Specific model or firmware revision numbers are not disclosed by the vendor advisory.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity, while the EPSS score of < 1% indicates a very low likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Attackers could exploit the flaw remotely using the radio interface; a rogue base station can trigger the out‑of‑bounds write whenever user equipment establishes a connection.

Generated by OpenCVE AI on July 21, 2026 at 15:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued firmware upgrades MOLY01267281 or MOLY01318201.
  • Reboot the device to apply the firmware update and ensure the fix takes effect.
  • Configure network equipment or the device itself to reject or require authentication for base stations that are not already authorized, reducing the chance of a rogue base station connection.

Generated by OpenCVE AI on July 21, 2026 at 15:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Write in MediaTek Modem Firmware Allows Remote Denial of Service via Rogue Base Station

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Modem Firmware Out‑of‑Bounds Write Enabling Remote Denial of Service

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Modem Firmware Out‑of‑Bounds Write Enabling Remote Denial of Service

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in MediaTek Modem Firmware Allowing Remote Denial of Service

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write in MediaTek Modem Firmware Allowing Remote Denial of Service

Sat, 11 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Modem Out-of-Bounds Write Leading to Remote Denial of Service via Rogue Base Station

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Modem Out-of-Bounds Write Leading to Remote Denial of Service via Rogue Base Station

Fri, 10 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in MediaTek Modem Firmware Allowing Remote Denial of Service

Thu, 09 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Out of Bounds Write in MediaTek Modem Firmware Allowing Remote Denial of Service

Wed, 08 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Leading to Remote Denial of Service on MediaTek Chipsets

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Leading to Remote Denial of Service on MediaTek Chipsets

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Missing bounds check in Modem firmware causes remote denial of service

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Missing bounds check in Modem firmware causes remote denial of service

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Modem Out-of-Bounds Write Allowing Remote Denial-of-Service via Rogue Base Station

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Allowing Remote Denial‑of‑Service via Rogue Base Station Modem Out-of-Bounds Write Allowing Remote Denial-of-Service via Rogue Base Station

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Allowing Remote Denial‑of‑Service via Rogue Base Station

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Modem Out-of-bounds Write Leading to Remote Denial of Service

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Out-of-bounds Write Leading to Remote Denial of Service

Fri, 03 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write in Modem Firmware Enables Remote Denial of Service

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Write in Modem Firmware Enables Remote Denial of Service

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Modem Firmware Out‑of‑Bounds Write Causing Remote Denial of Service

Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Modem Firmware Out‑of‑Bounds Write Causing Remote Denial of Service

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Allowing Remote Denial of Service

Wed, 01 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Modem Out‑of‑Bounds Write Allowing Remote Denial of Service

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Out Of Bounds Write in MediaTek Modem Leading to Remote Denial Of Service

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Out Of Bounds Write in MediaTek Modem Leading to Remote Denial Of Service

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01267281 / MOLY01318201; Issue ID: MSV-6486.
Weaknesses CWE-787
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-01T10:39:51.662Z

Reserved: 2025-11-03T01:30:59.014Z

Link: CVE-2026-20461

cve-icon Vulnrichment

Updated: 2026-07-01T10:34:38.735Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T15:15:08Z

Weaknesses