Sceawere
Vulnerability Detail
CVE-2026-20520UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Out-of-Bounds Write Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-787 Out-of-bounds Write
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-05T02:16:50.540Z",
"pubdate": "2026-10-05T02:16:50.540Z",
"executiveSummary": "A critical out-of-bounds (OOB) write vulnerability has been identified within the modem firmware, tracked under Issue ID MSV-8897 and Patch ID MOLY01778988.\nThe flaw stems from a critical absence of bounds checking during packet processing, which can be leveraged to achieve remote privilege escalation.\nThe vulnerability is exploitable without user interaction, provided the User Equipment (UE) establishes a connection with a malicious or rogue base station.\nSuccessful exploitation allows an attacker to gain elevated privileges on the modem subsystem, potentially enabling further compromise of the mobile device architecture.\nGiven the nature of the exploit—which occurs at the radio interface layer—it bypasses traditional application-level security controls, making it a significant risk to device integrity and user privacy.",
"technicalDetails": "The root cause of this vulnerability is a missing bounds check within the modem's packet parsing logic, leading to an out-of-bounds write condition. When the modem receives data frames from the base station, the internal buffers responsible for handling these payloads fail to validate the size of incoming data against the allocated memory segment.\nThe attack flow begins when an attacker operates a rogue base station, commonly referred to as an 'IMSI catcher' or similar radio-frequency (RF) spoofing equipment. The attacker forces a UE to perform a cell selection or handover to the malicious base station. Upon connection, the base station transmits specifically crafted, malformed radio resource control (RRC) or non-access stratum (NAS) messages.\nBecause the modem lacks proper bounds validation, the malicious input overwrites adjacent memory addresses outside the intended buffer. This memory corruption can be utilized by the attacker to overwrite critical data structures, function pointers, or return addresses within the modem's execution context.\nBy carefully constructing the payload, the attacker can hijack the control flow of the modem firmware. Since the modem typically operates with high privileges and direct access to radio hardware, gaining execution here allows the attacker to bypass the Trusted Execution Environment (TEE) or kernel-level protections if the modem shares memory space with the application processor.\nThis vulnerability is particularly dangerous because it does not require any execution privileges on the user-facing operating system, nor does it require user interaction. The exploitation is entirely transparent to the user, occurring silently over the air (OTA) via the established cellular connection. Post-exploitation impact includes the ability for an attacker to maintain persistent access, intercept traffic, or facilitate lateral movement into the device's main system-on-chip (SoC) memory."
}