Sceawere

Vulnerability Detail

CVE-2026-20520UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Modem Out-of-Bounds Write Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
17h ago
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Attack Type
CWE-787 Out-of-bounds Write
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-05T02:16:50.540Z",
  "pubdate": "2026-10-05T02:16:50.540Z",
  "executiveSummary": "A critical out-of-bounds (OOB) write vulnerability has been identified within the modem firmware, tracked under Issue ID MSV-8897 and Patch ID MOLY01778988.\nThe flaw stems from a critical absence of bounds checking during packet processing, which can be leveraged to achieve remote privilege escalation.\nThe vulnerability is exploitable without user interaction, provided the User Equipment (UE) establishes a connection with a malicious or rogue base station.\nSuccessful exploitation allows an attacker to gain elevated privileges on the modem subsystem, potentially enabling further compromise of the mobile device architecture.\nGiven the nature of the exploit—which occurs at the radio interface layer—it bypasses traditional application-level security controls, making it a significant risk to device integrity and user privacy.",
  "technicalDetails": "The root cause of this vulnerability is a missing bounds check within the modem's packet parsing logic, leading to an out-of-bounds write condition. When the modem receives data frames from the base station, the internal buffers responsible for handling these payloads fail to validate the size of incoming data against the allocated memory segment.\nThe attack flow begins when an attacker operates a rogue base station, commonly referred to as an 'IMSI catcher' or similar radio-frequency (RF) spoofing equipment. The attacker forces a UE to perform a cell selection or handover to the malicious base station. Upon connection, the base station transmits specifically crafted, malformed radio resource control (RRC) or non-access stratum (NAS) messages.\nBecause the modem lacks proper bounds validation, the malicious input overwrites adjacent memory addresses outside the intended buffer. This memory corruption can be utilized by the attacker to overwrite critical data structures, function pointers, or return addresses within the modem's execution context.\nBy carefully constructing the payload, the attacker can hijack the control flow of the modem firmware. Since the modem typically operates with high privileges and direct access to radio hardware, gaining execution here allows the attacker to bypass the Trusted Execution Environment (TEE) or kernel-level protections if the modem shares memory space with the application processor.\nThis vulnerability is particularly dangerous because it does not require any execution privileges on the user-facing operating system, nor does it require user interaction. The exploitation is entirely transparent to the user, occurring silently over the air (OTA) via the established cellular connection. Post-exploitation impact includes the ability for an attacker to maintain persistent access, intercept traffic, or facilitate lateral movement into the device's main system-on-chip (SoC) memory."
}
CVE-2026-20520: Modem Out-of-Bounds Write Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere