Description
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 / MOLY00814393; Issue ID: MSV-9041.
Published: 2026-10-05
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the modem component of MediaTek chipsets and arises from improper input validation. Maliciously crafted input can trigger a system crash, resulting in a remote denial of service. The attack requires no user interaction and does not grant additional privileges, meaning any device that connects to a rogue base station under attacker control can be impacted.

Affected Systems

MediaTek, Inc. MediaTek chipset devices. Specific model or firmware versions are not enumerated in the advisories.

Risk and Exploitability

The risk includes remote DoS for devices that have established a link with a rogue base station. Since user interaction or elevated privileges are not required, the attack surface is broad. Except for MediaTek's patch, the exploit is straightforward. The known EPSS score is unavailable and the vulnerability is not listed in KEV, but given the high impact of a DoS, it should be treated as a serious threat.

Generated by OpenCVE AI on October 5, 2026 at 03:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the MediaTek firmware patch (MOLY01870473 or MOLY00814393) to all affected devices.
  • Configure the network stack to restrict modem connectivity to authenticated base stations only, thereby limiting exposure to rogue stations.
  • After applying the patch and configuration changes, monitor modem logs for crash events to confirm the vulnerability has been mitigated before full deployment.

Generated by OpenCVE AI on October 5, 2026 at 03:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
Title Remote Denial-of-Service via Improper Modem Input Validation in MediaTek Chipset

Mon, 05 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 / MOLY00814393; Issue ID: MSV-9041.
Weaknesses CWE-617
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-10-05T01:39:54.320Z

Reserved: 2025-11-03T01:30:59.033Z

Link: CVE-2026-20525

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T02:16:51.163

Modified: 2026-10-05T02:16:51.163

Link: CVE-2026-20525

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T03:30:14Z

Weaknesses