Description
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
Published: 2026-09-07
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (local)
Action: Apply Patch
AI Analysis

Impact

The vulnerability occurs when the Modem firmware performs improper input validation, which can cause a system crash. The resulting failure is a local denial of service that requires user execution privileges. Exploitation necessitates active user interaction; the attacker must supply crafted input while possessing local privileges on the device.

Affected Systems

Affected systems are MediaTek chipset devices. No specific product versions or firmware releases are listed in the advisory, so all devices using the vulnerable modem component should be assumed at risk until a patch is applied.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. The CVSS score of 5.5 indicates medium severity. The attack vector is local, requiring a user with execution privileges and physical or logical access to the device. A successful exploit would lead to a system crash but would not provide remote code execution or further privilege escalation, resulting in a moderate risk for environments where device availability is critical and local privilege escalation is possible.

Generated by OpenCVE AI on September 7, 2026 at 14:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor patch identified by patch ID MOLY01810811 (Issue ID MSV-9232).
  • Disable or restrict the modem functionality if it is unnecessary for the device’s operation to reduce the attack surface.
  • Limit local user privileges to prevent execution of malicious inputs that could trigger the crash.

Generated by OpenCVE AI on September 7, 2026 at 14:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek mt2716
Mediatek mt2716 Firmware
Mediatek mt6835
Mediatek mt6835 Firmware
Mediatek mt6858
Mediatek mt6858 Firmware
Mediatek mt6878
Mediatek mt6878 Firmware
Mediatek mt6881
Mediatek mt6881 Firmware
Mediatek mt6897
Mediatek mt6897 Firmware
Mediatek mt6899
Mediatek mt6899 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt6993
Mediatek mt6993 Firmware
Mediatek mt8668
Mediatek mt8668 Firmware
Mediatek mt8676
Mediatek mt8676 Firmware
Mediatek mt8678
Mediatek mt8678 Firmware
Mediatek mt8755
Mediatek mt8755 Firmware
Mediatek mt8775
Mediatek mt8775 Firmware
Mediatek mt8792
Mediatek mt8792 Firmware
Mediatek mt8793
Mediatek mt8793 Firmware
Mediatek mt8863
Mediatek mt8863 Firmware
Mediatek mt8873
Mediatek mt8873 Firmware
Mediatek mt8883
Mediatek mt8883 Firmware
CPEs cpe:2.3:h:mediatek:mt2716:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6858:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6881:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6982vb:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6986:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6988:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6991:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6993:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8668:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8676:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8678:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8755:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8775:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8792:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8793:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8863:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8883:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2716_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6835_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6858_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6878_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6881_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6897_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6899_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6982vb_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6986_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6988_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6991_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6993_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8668_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8676_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8678_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8755_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8775_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8792_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8793_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8863_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8873_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8883_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek mt2716
Mediatek mt2716 Firmware
Mediatek mt6835
Mediatek mt6835 Firmware
Mediatek mt6858
Mediatek mt6858 Firmware
Mediatek mt6878
Mediatek mt6878 Firmware
Mediatek mt6881
Mediatek mt6881 Firmware
Mediatek mt6897
Mediatek mt6897 Firmware
Mediatek mt6899
Mediatek mt6899 Firmware
Mediatek mt6982vb
Mediatek mt6982vb Firmware
Mediatek mt6986
Mediatek mt6986 Firmware
Mediatek mt6988
Mediatek mt6988 Firmware
Mediatek mt6991
Mediatek mt6991 Firmware
Mediatek mt6993
Mediatek mt6993 Firmware
Mediatek mt8668
Mediatek mt8668 Firmware
Mediatek mt8676
Mediatek mt8676 Firmware
Mediatek mt8678
Mediatek mt8678 Firmware
Mediatek mt8755
Mediatek mt8755 Firmware
Mediatek mt8775
Mediatek mt8775 Firmware
Mediatek mt8792
Mediatek mt8792 Firmware
Mediatek mt8793
Mediatek mt8793 Firmware
Mediatek mt8863
Mediatek mt8863 Firmware
Mediatek mt8873
Mediatek mt8873 Firmware
Mediatek mt8883
Mediatek mt8883 Firmware

Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Denial of Service via Improper Input Validation

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mediatek Chipset
Vendors & Products Mediatek
Mediatek mediatek Chipset

Mon, 07 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
Title MediaTek Modem Denial of Service via Improper Input Validation

Mon, 07 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
Weaknesses CWE-295
References

Subscriptions

Mediatek Mediatek Chipset Mt2716 Mt2716 Firmware Mt6835 Mt6835 Firmware Mt6858 Mt6858 Firmware Mt6878 Mt6878 Firmware Mt6881 Mt6881 Firmware Mt6897 Mt6897 Firmware Mt6899 Mt6899 Firmware Mt6982vb Mt6982vb Firmware Mt6986 Mt6986 Firmware Mt6988 Mt6988 Firmware Mt6991 Mt6991 Firmware Mt6993 Mt6993 Firmware Mt8668 Mt8668 Firmware Mt8676 Mt8676 Firmware Mt8678 Mt8678 Firmware Mt8755 Mt8755 Firmware Mt8775 Mt8775 Firmware Mt8792 Mt8792 Firmware Mt8793 Mt8793 Firmware Mt8863 Mt8863 Firmware Mt8873 Mt8873 Firmware Mt8883 Mt8883 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-09-07T10:41:03.588Z

Reserved: 2025-11-03T01:30:59.027Z

Link: CVE-2026-20500

cve-icon Vulnrichment

Updated: 2026-09-07T10:40:55.573Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T02:17:18.673

Modified: 2026-09-09T02:55:11.390

Link: CVE-2026-20500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T14:15:16Z

Weaknesses
  • CWE-295

    Improper Certificate Validation