Description
In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability stems from improper input validation in the Cellular Modem component, which can trigger a denial of service without the need for elevated privileges. The flaw allows a remote attacker to cause the modem to become unresponsive or crash, potentially disrupting cellular connectivity. According to the description, user interaction is not required for exploitation, meaning an attacker could initiate the exploit from an adjacent or nearby location. The likely attack vector is a remote, proximal or adjacent attack that targets the modem’s input processing.

Affected Systems

The affected product is the Android Cellular Modem component of Google Android devices. No specific device models or version numbers are listed in the available data, so all devices that incorporate this modem component are potentially impacted until an official patch is applied.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity vulnerability. The EPSS score is < 1%, indicating that the probability of exploitation is very low. The flaw is not currently listed in the CISA KEV catalog. Exploitation requires no user interaction and no additional privileges, which lowers the barrier to attack but results in a loss of connectivity rather than a compromise of the device or data. Attackers would need to deliver malformed input to the modem, which may be achievable through broadcast or other input channels that the modem processes.

Generated by OpenCVE AI on September 17, 2026 at 08:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Android security patch that addresses the Cellular Modem input validation flaw
  • Update the device to the newest Android OS release to ensure the modem component contains the fix
  • If a patch is not yet available, disable the cellular modem service or remove the modem from the device until an update is released

Generated by OpenCVE AI on September 17, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Input Validation in Cellular Modem

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Wed, 16 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Title Denial of Service via Improper Input Validation in Cellular Modem

Tue, 15 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google android
Vendors & Products Google
Google android

Tue, 15 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote (proximal/adjacent) denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Google_Devices

Published:

Updated: 2026-09-16T16:02:27.835Z

Reserved: 2026-06-23T16:20:45.087Z

Link: CVE-2026-56975

cve-icon Vulnrichment

Updated: 2026-09-15T20:52:11.419Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T19:17:29.440

Modified: 2026-09-16T19:24:44.153

Link: CVE-2026-56975

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T08:30:15Z

Weaknesses
  • CWE-20

    Improper Input Validation