Sceawere
Vulnerability Detail
CVE-2026-20525UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Remote Denial of Service
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-617 Reachable Assertion
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 / MOLY00814393; Issue ID: MSV-9041.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T02:16:51.163Z",
"pubdate": "2026-10-05T02:16:51.163Z",
"executiveSummary": "This vulnerability involves an improper input validation flaw within the Modem firmware, leading to a system crash and subsequent remote denial of service (DoS).\nThe issue resides in the modem's handling of network-layer data received from base stations.\nAn attacker can exploit this by operating a rogue base station to transmit specially crafted, malformed packets to a target User Equipment (UE).\nSuccessful exploitation results in the unexpected termination of modem services, causing a loss of cellular connectivity and device functionality.\nThe vulnerability does not require user interaction, authentication, or elevated privileges to execute.\nRisk is significant as it facilitates remote service disruption without physical access to the device.",
"technicalDetails": "The root cause of this vulnerability is inadequate validation of input data processed by the Modem firmware. When the modem receives data packets from a base station, the parsing logic fails to verify the integrity and structure of incoming payloads before performing operations on them.\nThe exploitation flow begins when a target device (UE) attempts to camp on or connect to a malicious base station, often referred to as a rogue base station or IMSI-catcher, configured by the attacker. By design, the modem continuously monitors and processes signaling messages sent over the air interface.\nThe attacker sends a maliciously crafted packet designed to trigger an error during the parsing process. Because the input validation routine lacks sufficient boundary checking or format verification, the malformed data causes the modem software to enter an undefined or error state. This state triggers an unhandled exception or a memory access violation, leading to an immediate system crash or a hang of the modem process.\nThis vulnerability is classified as an improper input validation issue that directly impacts the availability of the modem component. The exposure is remote, as the trigger occurs over the wireless radio frequency interface. Since the modem typically operates with high-level system privileges or within a protected subsystem, crashing the modem process is sufficient to cause a total loss of cellular network availability (DoS) for the device.\nNo pre-existing execution privileges or authentication are required on the target device, as the exploitation happens via the modem's low-level protocol stack implementation. The lack of validation allows the attacker to influence the internal execution flow of the modem firmware from an external, potentially untrusted network source. The impact is limited to a denial of service, as the device becomes unable to communicate over the cellular network until a manual or automated reset of the modem component occurs.\nAffected components include the modem subsystem responsible for parsing incoming network signaling messages. Specific patches identified for this issue are MOLY01870473 and MOLY00814393, tracked under Issue ID MSV-9041."
}