mt8678_firmware vulnerabilities
CVEs whose affected-version data names the mt8678_firmware package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
4 CVEsRSS
CVE-2026-20503Medium· 5.3In Modem, there is a possible system crash due to a missing bounds check
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges need…
CVE-2026-20502High· 8.4In vdec, there is a possible out of bounds write due to a missing bounds check
In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
CVE-2026-20501High· 8.4In vdec, there is a possible out of bounds write due to a heap buffer overflow
In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: A…
CVE-2026-20500Medium· 5.5In Modem, there is a possible system crash due to improper input validation
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID:…