{"id":"CVE-2026-20503","title":"In Modem, there is a possible system crash due to a missing bounds check","summary":"In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-617"],"vendor":"mediatek","product":"mt2716_firmware","affected":["mt2716_firmware","mt2735_firmware","mt2737_firmware","mt6813_firmware","mt6833_firmware","mt6835_firmware","mt6853_firmware","mt6855_firmware","mt6858_firmware","mt6873_firmware","mt6875_firmware","mt6877_firmware","mt6878_firmware","mt6879_firmware","mt6880_firmware","mt6881_firmware","mt6883_firmware","mt6885_firmware","mt6886_firmware","mt6889_firmware","mt6890_firmware","mt6891_firmware","mt6893_firmware","mt6895_firmware","mt6896_firmware","mt6897_firmware","mt6899_firmware","mt6980_firmware","mt6982vb_firmware","mt6983_firmware","mt6985_firmware","mt6986_firmware","mt6988_firmware","mt6989_firmware","mt6990_firmware","mt6991_firmware","mt6993_firmware","mt8668_firmware","mt8673_firmware","mt8675_firmware","mt8676_firmware","mt8678_firmware","mt8755_firmware","mt8771_firmware","mt8775_firmware","mt8791_firmware","mt8791t_firmware","mt8792_firmware","mt8793_firmware","mt8795t_firmware","mt8796_firmware","mt8797_firmware","mt8798_firmware","mt8863_firmware","mt8873_firmware","mt8883_firmware","mt8893_firmware"],"published":"2026-09-07","updated":"2026-09-09","sourceUpdated":"2026-09-09T02:55:29.153","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20503","references":[{"url":"https://www.mediatek.com/product-security-bulletin/September-2026","label":"security@mediatek.com"}],"tags":["nvd"],"epss":0.00192,"epssPercentile":0.09149,"ingestedAt":"2026-09-07T12:10:15.852Z","slug":"CVE-2026-20503","body":"## Overview\n\nIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.\n\n## Affected\n\n- `mt2716_firmware`\n- `mt2735_firmware`\n- `mt2737_firmware`\n- `mt6813_firmware`\n- `mt6833_firmware`\n- `mt6835_firmware`\n- `mt6853_firmware`\n- `mt6855_firmware`\n- `mt6858_firmware`\n- `mt6873_firmware`\n- `mt6875_firmware`\n- `mt6877_firmware`\n- `mt6878_firmware`\n- `mt6879_firmware`\n- `mt6880_firmware`\n- `mt6881_firmware`\n- `mt6883_firmware`\n- `mt6885_firmware`\n- `mt6886_firmware`\n- `mt6889_firmware`\n- `mt6890_firmware`\n- `mt6891_firmware`\n- `mt6893_firmware`\n- `mt6895_firmware`\n- `mt6896_firmware`\n- `mt6897_firmware`\n- `mt6899_firmware`\n- `mt6980_firmware`\n- `mt6982vb_firmware`\n- `mt6983_firmware`\n- `mt6985_firmware`\n- `mt6986_firmware`\n- `mt6988_firmware`\n- `mt6989_firmware`\n- `mt6990_firmware`\n- `mt6991_firmware`\n- `mt6993_firmware`\n- `mt8668_firmware`\n- `mt8673_firmware`\n- `mt8675_firmware`\n- `mt8676_firmware`\n- `mt8678_firmware`\n- `mt8755_firmware`\n- `mt8771_firmware`\n- `mt8775_firmware`\n- `mt8791_firmware`\n- `mt8791t_firmware`\n- `mt8792_firmware`\n- `mt8793_firmware`\n- `mt8795t_firmware`\n- `mt8796_firmware`\n- `mt8797_firmware`\n- `mt8798_firmware`\n- `mt8863_firmware`\n- `mt8873_firmware`\n- `mt8883_firmware`\n- `mt8893_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}