Description
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
Published: 2026-07-01
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permissions bypass in the modem component of MediaTek chipsets, classified as CWE-280. An attacker who already has System privilege can execute code through the modem to elevate privileges, allowing local privilege escalation. The flaw does not require user interaction, so anyone with local access and System rights can exploit it, potentially compromising the entire device.

Affected Systems

MediaTek chipsets are affected. The issue resides in the modem component. No specific firmware or model versions were listed; the vulnerability applies to any firmware that includes the vulnerable modem code, until the patch ID MOLY01716533 is applied.

Risk and Exploitability

The CVSS score of 6.7 indicates medium severity, driven by local privilege escalation potential when a System privilege user can bypass permissions in the modem. The EPSS score of less than 1 % implies a low probability of exploitation at the time of this analysis, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires local code execution, which is feasible for an attacker with System-level access but not remotely or over the network. Thus, while the risk is moderate relative to ordinary privilege escalation flaws, the lack of user interaction means that once System privileges exist the flaw can be leveraged quickly.

Generated by OpenCVE AI on July 16, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Mediatek firmware update Patch ID MOLY01716533 to fix the permissions bypass in the modem.
  • Disable or restrict modem services and functions that are not essential for your deployment to limit the attack surface for privilege escalation.
  • Enable secure boot or firmware integrity verification, and monitor device logs for unexpected modem activity to detect potential exploitation attempts.

Generated by OpenCVE AI on July 16, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Privilege Escalation via Permissions Bypass

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enabling Local Privilege Escalation

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enabling Local Privilege Escalation

Sat, 11 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on MediaTek Devices

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on MediaTek Devices

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation through Modem Permissions Bypass on MediaTek Chipsets

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation through Modem Permissions Bypass on MediaTek Chipsets

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Permissions Bypass in Modem Enables Local Privilege Escalation on MediaTek Chipsets

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Permissions Bypass in Modem Enables Local Privilege Escalation on MediaTek Chipsets

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privileged Escalation via Permissions Bypass in MediaTek Modem

Sun, 05 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Privileged Escalation via Permissions Bypass in MediaTek Modem

Sat, 04 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Leading to Local Privilege Escalation

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Leading to Local Privilege Escalation

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass on MediaTek Chipsets

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass on MediaTek Chipsets

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Bypass in MediaTek Modem

Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Bypass in MediaTek Modem

Wed, 01 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on Mediatek Chipsets

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on Mediatek Chipsets

Wed, 01 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in MediaTek Modem via Permissions Bypass

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in MediaTek Modem via Permissions Bypass

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
Weaknesses CWE-280
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-02T03:55:18.676Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20463

cve-icon Vulnrichment

Updated: 2026-07-01T10:35:47.748Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:00:04Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges