CVE-2026-20503Medium· 5.3▾ SunlitIn Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.
mt2716_firmwaremt2735_firmwaremt2737_firmwaremt6813_firmwaremt6833_firmwaremt6835_firmwaremt6853_firmwaremt6855_firmwaremt6858_firmwaremt6873_firmwaremt6875_firmwaremt6877_firmwaremt6878_firmwaremt6879_firmwaremt6880_firmwaremt6881_firmwaremt6883_firmwaremt6885_firmwaremt6886_firmwaremt6889_firmwaremt6890_firmwaremt6891_firmwaremt6893_firmwaremt6895_firmwaremt6896_firmwaremt6897_firmwaremt6899_firmwaremt6980_firmwaremt6982vb_firmwaremt6983_firmwaremt6985_firmwaremt6986_firmwaremt6988_firmwaremt6989_firmwaremt6990_firmwaremt6991_firmwaremt6993_firmwaremt8668_firmwaremt8673_firmwaremt8675_firmwaremt8676_firmwaremt8678_firmwaremt8755_firmwaremt8771_firmwaremt8775_firmwaremt8791_firmwaremt8791t_firmwaremt8792_firmwaremt8793_firmwaremt8795t_firmwaremt8796_firmwaremt8797_firmwaremt8798_firmwaremt8863_firmwaremt8873_firmwaremt8883_firmwaremt8893_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-20504Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
CVE-2026-20500Medium· 5.5In Modem, there is a possible system crash due to improper input validation
CVE-2026-20502High· 8.4In vdec, there is a possible out of bounds write due to a missing bounds check
CVE-2026-20501High· 8.4In vdec, there is a possible out of bounds write due to a heap buffer overflow
CVE-2025-12131Medium· 6.5A truncated 802.15.4 packet can lead to an assert, resulting in a denial of service.
CVE-2026-94623High· 7.5vLLM through 0.29.0 contains a denial of service vulnerability in the NIXL connector's prefix caching implementation that fails to properly validate block counts across multi-prompt completion requests in prefill/decode disaggregated dep…