{"id":"CVE-2026-20504","title":"In Modem, there is a possible system crash due to a missing bounds check","summary":"In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-617"],"vendor":"mediatek","product":"mt2735_firmware","affected":["mt2735_firmware","mt6833_firmware","mt6853_firmware","mt6855_firmware","mt6873_firmware","mt6875_firmware","mt6877_firmware","mt6880_firmware","mt6883_firmware","mt6885_firmware","mt6889_firmware","mt6890_firmware","mt6891_firmware","mt6893_firmware","mt8675_firmware","mt8771_firmware","mt8791_firmware","mt8791t_firmware","mt8797_firmware"],"published":"2026-09-07","updated":"2026-09-09","sourceUpdated":"2026-09-09T02:55:33.787","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-20504","references":[{"url":"https://www.mediatek.com/product-security-bulletin/September-2026","label":"security@mediatek.com"}],"tags":["nvd"],"epss":0.00192,"epssPercentile":0.09149,"ingestedAt":"2026-09-07T12:10:15.894Z","slug":"CVE-2026-20504","body":"## Overview\n\nIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.\n\n## Affected\n\n- `mt2735_firmware`\n- `mt6833_firmware`\n- `mt6853_firmware`\n- `mt6855_firmware`\n- `mt6873_firmware`\n- `mt6875_firmware`\n- `mt6877_firmware`\n- `mt6880_firmware`\n- `mt6883_firmware`\n- `mt6885_firmware`\n- `mt6889_firmware`\n- `mt6890_firmware`\n- `mt6891_firmware`\n- `mt6893_firmware`\n- `mt8675_firmware`\n- `mt8771_firmware`\n- `mt8791_firmware`\n- `mt8791t_firmware`\n- `mt8797_firmware`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}