Junglewise Threat Intelligence

CVE-2026-20504: MediaTek Modem denial of service due to missing bounds check

CVE-2026-20504 · Severity: medium · CVSS 5.3 · Published 2026-09-07

Technologies: MediaTek Mt8797 Firmware, MediaTek MT8791, MediaTek Mt6880, MediaTek Mt8675, MediaTek Mt6885, MediaTek Mt6873 Firmware, MediaTek Mt8675 Firmware, MediaTek Mt6855 Firmware, MediaTek Mt6883, MediaTek Mt6875, MediaTek Mt8791t, MediaTek Mt6855, MediaTek Mt8771, MediaTek Mt6877 Firmware, MediaTek Mt8791t Firmware, MediaTek Mt6877, MediaTek Mt6833 Firmware, MediaTek Mt6853 Firmware, MediaTek Mt6889, MediaTek Mt8797, MediaTek Mt6853, MediaTek Mt8791 Firmware, MediaTek Mt2735 Firmware, MediaTek Mt8771 Firmware, MediaTek MT2735, MediaTek Mt6889 Firmware, MediaTek MT6891, MediaTek Mt6890 Firmware, MediaTek MT6833, MediaTek Mt6891 Firmware, MediaTek Mt6875 Firmware, MediaTek Mt6893 Firmware, MediaTek Mt6893, MediaTek Mt6883 Firmware, MediaTek MT6873, MediaTek Mt6885 Firmware, MediaTek Modem, MediaTek Mt6880 Firmware, MediaTek Mt6890. Vendors: MediaTek.

Executive brief

MediaTek modems are communication processors used in smartphones and IoT devices to handle cellular connectivity. A missing bounds check in the modem firmware can cause a system crash when a device connects to a rogue base station controlled by an attacker, resulting in service disruption. No special privileges or user interaction are required to exploit this vulnerability.

Technical details

This vulnerability is a denial-of-service flaw caused by improper bounds checking in the modem subcomponent, allowing an out-of-bounds memory access or crash condition. The attack is triggered over the network when a user equipment (UE) connects to a malicious base station controlled by the attacker. The attacker sends specially crafted input that bypasses validation, causing the modem to crash and temporarily disabling cellular connectivity. No authentication or elevated privileges are required, and the attack succeeds without any user interaction. A patch is available (MOLY00755024).

Affected products

  • MediaTek Modem MT2716, MT6835, MT6858, MT6878, MT6881, MT6897, MT6899, MT6982VB, MT6986, MT6988, MT6991, MT6993, MT8668, MT8676, MT8678, MT8755, MT8775, MT8792, MT8793, MT8863, MT8873, MT8883

Timeline

  • 2026-09-07: disclosed

References

Related threats