Description
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Published: 2026-09-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Patch Immediately
AI Analysis

Impact

A missing bounds check in the MediaTek chipset modem can cause a system crash, providing an attacker control over a rogue base station a means to deny service remotely. The flaw requires no special privileges or user interaction, enabling straightforward exploitation from a compromised UE’s perspective. The impact is loss of connectivity and potential service interruption for affected devices, though no integrity or confidentiality compromise is indicated.

Affected Systems

The vulnerability affects devices powered by MediaTek chipsets as sold by MediaTek, Inc. The affected firmware or modem software variants are not enumerated in the data, so any firmware build with the identified bounds check omission could be at risk.

Risk and Exploitability

The CVSS score is 5.3, and EPSS data is unavailable, but the lack of required privileges and absence of user interaction suggest a moderate exploitability. The CVE is not listed in CISA’s KEV catalog, indicating there are no confirmed widespread exploitation incidents yet. An attacker could trigger the crash by sending specially crafted packets from a rogue base station to a connected UE, causing a denial of service without further actions.

Generated by OpenCVE AI on September 7, 2026 at 13:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the firmware patch with Patch ID MOLY00755024 released by MediaTek
  • After patching, monitor device stability and network connectivity to confirm the denial-of-service issue is resolved
  • If the patch is not yet available for the specific device, temporarily restrict the modem's connectivity to trusted networks or disable the modem until the patch is applied

Generated by OpenCVE AI on September 7, 2026 at 13:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt6833
Mediatek mt6833 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6873
Mediatek mt6873 Firmware
Mediatek mt6875
Mediatek mt6875 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6891
Mediatek mt6891 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt8675
Mediatek mt8675 Firmware
Mediatek mt8771
Mediatek mt8771 Firmware
Mediatek mt8791
Mediatek mt8791 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8797
Mediatek mt8797 Firmware
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6833_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6853_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6855_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6873_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6875_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6877_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6880_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6883_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6885_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6889_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6890_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6891_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt6893_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8675_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8771_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8791t_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:mt8797_firmware:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt2735 Firmware
Mediatek mt6833
Mediatek mt6833 Firmware
Mediatek mt6853
Mediatek mt6853 Firmware
Mediatek mt6855
Mediatek mt6855 Firmware
Mediatek mt6873
Mediatek mt6873 Firmware
Mediatek mt6875
Mediatek mt6875 Firmware
Mediatek mt6877
Mediatek mt6877 Firmware
Mediatek mt6880
Mediatek mt6880 Firmware
Mediatek mt6883
Mediatek mt6883 Firmware
Mediatek mt6885
Mediatek mt6885 Firmware
Mediatek mt6889
Mediatek mt6889 Firmware
Mediatek mt6890
Mediatek mt6890 Firmware
Mediatek mt6891
Mediatek mt6891 Firmware
Mediatek mt6893
Mediatek mt6893 Firmware
Mediatek mt8675
Mediatek mt8675 Firmware
Mediatek mt8771
Mediatek mt8771 Firmware
Mediatek mt8791
Mediatek mt8791 Firmware
Mediatek mt8791t
Mediatek mt8791t Firmware
Mediatek mt8797
Mediatek mt8797 Firmware

Mon, 07 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Title Modem Bounds Check Omission Causing Remote Denial of Service on MediaTek Chipsets

Mon, 07 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek, Inc.
Mediatek, Inc. mediatek Chipset
Vendors & Products Mediatek, Inc.
Mediatek, Inc. mediatek Chipset

Mon, 07 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Weaknesses CWE-617
References

Subscriptions

Mediatek Mt2735 Mt2735 Firmware Mt6833 Mt6833 Firmware Mt6853 Mt6853 Firmware Mt6855 Mt6855 Firmware Mt6873 Mt6873 Firmware Mt6875 Mt6875 Firmware Mt6877 Mt6877 Firmware Mt6880 Mt6880 Firmware Mt6883 Mt6883 Firmware Mt6885 Mt6885 Firmware Mt6889 Mt6889 Firmware Mt6890 Mt6890 Firmware Mt6891 Mt6891 Firmware Mt6893 Mt6893 Firmware Mt8675 Mt8675 Firmware Mt8771 Mt8771 Firmware Mt8791 Mt8791 Firmware Mt8791t Mt8791t Firmware Mt8797 Mt8797 Firmware
Mediatek, Inc. Mediatek Chipset
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-09-07T10:36:49.120Z

Reserved: 2025-11-03T01:30:59.028Z

Link: CVE-2026-20504

cve-icon Vulnrichment

Updated: 2026-09-07T10:36:43.282Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-07T02:17:19.143

Modified: 2026-09-09T02:55:33.787

Link: CVE-2026-20504

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T13:30:16Z

Weaknesses