Junglewise Threat Intelligence

CVE-2026-20459: MediaTek Chipset improper input validation in Modem

CVE-2026-20459 · Severity: info · Published 2026-07-01

Technologies: MediaTek Chipset. Vendors: MediaTek.

Executive brief

A vulnerability exists in the modem component of several MediaTek chipsets used in mobile devices. If a device connects to a malicious base station controlled by an attacker, it could cause the modem to crash, leading to a total loss of cellular connectivity. This is a denial-of-service attack that does not require any user interaction or special permissions on the device.

Technical details

An improper input validation vulnerability exists in the MediaTek Modem firmware. An attacker can exploit this by operating a rogue base station (eNodeB/gNodeB) that sends malformed or unexpected inputs to a connecting User Equipment (UE). Successful exploitation results in a system crash of the modem component, causing a denial of service. No additional execution privileges or user interactions are required for the attack. MediaTek has released a patch under ID MOLY01816800 to address this issue.

Affected products

  • MediaTek, Inc. MediaTek chipset MT2716, MT2735, MT2737, MT6739, MT6761, MT6762, MT6763, MT6765, MT6767, MT6768, MT6769, MT6771, MT6779, MT6781, MT6783, MT6785, MT6789, MT6813, MT6833, MT6835, MT6853, MT6855, MT6858, MT6873, MT6875, MT6877, MT6878, MT6879, MT6880, MT6881, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6896, MT6897, MT6899, MT6980, MT6982, MT6983, MT6985, MT6986, MT6986D, MT6988

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References

Related threats