Skip to content
CodeAuditAgent

CVE-2026-20432

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.

Weakness

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.

Affected products

  • mediatek mt2735_firmware
  • mediatek mt2735
  • mediatek mt2737_firmware
  • mediatek mt2737
  • mediatek mt6779_firmware
  • mediatek mt6779
  • mediatek mt6781_firmware
  • mediatek mt6781

References

Find the bug before an attacker does.

Sign in with GitHub and run your first audit in under a minute. The free plan needs no credit card.