Junglewise Threat Intelligence

CVE-2026-20431: MediaTek Chipset denial of service in Modem

CVE-2026-20431 · Severity: medium · CVSS 6.5 · Published 2026-04-07

Technologies: MediaTek MT8883, MediaTek MT8873, MediaTek MT8676, MediaTek MT8755, MediaTek MT8863, MediaTek Mt6878, MediaTek Mt6991, MediaTek MT6993, MediaTek MT6813, MediaTek Mt6897, MediaTek MT8792, MediaTek Mt6835, MediaTek MT8775, MediaTek Mt6986, MediaTek Mt8668, MediaTek Mt8793, MediaTek Mt6899, MediaTek MT8678. Vendors: MediaTek.

Executive brief

A vulnerability in certain MediaTek chipsets could allow an attacker to crash a mobile device's modem, leading to a loss of cellular connectivity. This occurs when a device connects to a malicious base station (rogue cell tower) controlled by the attacker. An exploit would result in a denial of service, preventing the user from making calls or using mobile data until the system is recovered.

Technical details

A logic error in the MediaTek modem firmware (CWE-770) leads to a system crash when the User Equipment (UE) interacts with a rogue base station. The vulnerability is exploitable via an adjacent network vector without requiring authentication or user interaction. An attacker in physical proximity can deploy a rogue base station to trigger a remote denial of service (DoS) on affected devices. MediaTek has released Patch ID MOLY01106496 to address this issue across multiple chipset models including MT68xx, MT69xx, and MT8xxx series.

Affected products

  • MediaTek MT6813
  • MediaTek MT6815
  • MediaTek MT6835
  • MediaTek MT6878
  • MediaTek MT6897
  • MediaTek MT6899
  • MediaTek MT6986
  • MediaTek MT6991
  • MediaTek MT6993
  • MediaTek MT8668
  • MediaTek MT8676
  • MediaTek MT8678
  • MediaTek MT8755
  • MediaTek MT8775
  • MediaTek MT8792
  • MediaTek MT8793
  • MediaTek MT8863
  • MediaTek MT8873
  • MediaTek MT8883

Timeline

  • 2026-04-07: advisory: MediaTek published the security bulletin
  • 2026-04-07: disclosed: CVE published to NVD

References