Description
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
Published: 2026-07-01
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a permissions bypass in the modem component of MediaTek chipsets, classified as CWE-280. An attacker who already has System privilege can execute code through the modem to elevate privileges, allowing local privilege escalation. The flaw does not require user interaction, so anyone with local access and System rights can exploit it, potentially compromising the entire device.

Affected Systems

MediaTek chipsets are affected. The issue resides in the modem component. No specific firmware or model versions were listed; the vulnerability applies to any firmware that includes the vulnerable modem code, until the patch ID MOLY01716533 score of 6.7 indicates medium severity, driven by local privilege escalation potential when a System privilege user can bypass permissions in the modem.

Risk and Exploitability

The CVSS score of 6.7 classifies this flaw as medium severity, indicating modest but non-negligible risk. The EPSS score of less than 1 % suggests a low likelihood of exploitation at present, and the vulnerability is not currently listed in CISA KEV catalog. Because the already possess System privileges and local code execution, exploitation is limited to devices with full system access; remote exploitation is not supported. Nevertheless, once System privileges exist, the permissions bypass can be used to elevate privileges quickly, potentially compromising all components of the affected MediaTek modem.

Generated by OpenCVE AI on August 3, 2026 at 06:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Mediatek firmware update Patch ID MOLY01716533 to fix the permissions bypass in the modem.
  • Disable or restrict modem services and functions that are not essential for your deployment to limit the attack surface for verification, and monitor device logs for unexpected modem activity to detect potential exploitation attempts.
  • Restrict local user accounts that can access the modem interface and enforce least‑privilege execution for applications interacting with the modem to reduce the attack surface.

Generated by OpenCVE AI on August 3, 2026 at 06:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Permissions Bypass in MediaTek Modem Enables Local Privilege Escalation

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Permissions Bypass Leading to Local Privilege Escalation

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Permissions Bypass Leading to Local Privilege Escalation

Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Privilege Escalation via Permissions Bypass

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Privilege Escalation via Permissions Bypass

Tue, 14 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enabling Local Privilege Escalation

Sun, 12 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enabling Local Privilege Escalation

Sat, 11 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on MediaTek Devices

Fri, 10 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on MediaTek Devices

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation through Modem Permissions Bypass on MediaTek Chipsets

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation through Modem Permissions Bypass on MediaTek Chipsets

Wed, 08 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Permissions Bypass in Modem Enables Local Privilege Escalation on MediaTek Chipsets

Mon, 06 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Permissions Bypass in Modem Enables Local Privilege Escalation on MediaTek Chipsets

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privileged Escalation via Permissions Bypass in MediaTek Modem

Sun, 05 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Privileged Escalation via Permissions Bypass in MediaTek Modem

Sat, 04 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Leading to Local Privilege Escalation

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Leading to Local Privilege Escalation

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass on MediaTek Chipsets

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Modem Permissions Bypass on MediaTek Chipsets

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Bypass in MediaTek Modem

Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Permissions Bypass in MediaTek Modem

Wed, 01 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on Mediatek Chipsets

Wed, 01 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Modem Permissions Bypass Enables Local Privilege Escalation on Mediatek Chipsets

Wed, 01 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Wed, 01 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in MediaTek Modem via Permissions Bypass

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation in MediaTek Modem via Permissions Bypass

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
Weaknesses CWE-280
References

Subscriptions

Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-07-02T03:55:18.676Z

Reserved: 2025-11-03T01:30:59.015Z

Link: CVE-2026-20463

cve-icon Vulnrichment

Updated: 2026-07-01T10:35:47.748Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:15:04Z

Weaknesses
  • CWE-280

    Improper Handling of Insufficient Permissions or Privileges