Sceawere

Vulnerability Detail

CVE-2026-20527UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Modem Missing Bounds Check Crash

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
17h ago
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Attack Type
CWE-129 Improper Validation of Array Index
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01864925 / MOLY01210562; Issue ID: MSV-8303.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T02:16:51.397Z",
  "pubdate": "2026-10-05T02:16:51.397Z",
  "executiveSummary": "A critical vulnerability exists within the Modem software component, specifically due to a missing bounds check. This flaw allows an attacker operating a rogue base station to induce a system crash on a target User Equipment (UE).\nThe vulnerability is classified as a denial-of-service (DoS) condition. It can be triggered remotely without requiring user interaction or elevated execution privileges. Because the vulnerability is exploited at the baseband level, the device's connectivity to a malicious infrastructure is the primary requirement for successful exploitation.\nThe risk is significant as it provides a pathway for an attacker to effectively disable a mobile device's communication capabilities by forcing a modem reset or kernel panic. The exploitation occurs during the radio resource control or signaling phases between the rogue base station and the target UE, bypassing the need for higher-level application-layer privileges.",
  "technicalDetails": "The root cause of the vulnerability is the absence of rigorous bounds checking during the processing of data packets or signaling messages received from a cellular base station. When the modem firmware parses incoming payloads, it fails to validate the size or structure of the data against the allocated buffer memory. This creates an out-of-bounds access scenario that triggers a memory corruption event.\nThe attack flow begins when a target UE initiates a connection or is forced to perform a handover to an attacker-controlled rogue base station (e.g., an IMSI catcher or a malicious small cell). Once the physical and link-layer connections are established, the rogue base station transmits a specially crafted signaling message designed to exploit the missing bounds check.\nUpon receipt, the Modem parsing logic attempts to process the payload without verifying if the data length exceeds the destination buffer size. This leads to a heap or stack-based buffer overflow or an illegal memory access depending on the specific implementation of the memory management unit and the modem architecture. The resulting access violation forces the modem processor to halt, causing a system-wide crash or an unrecoverable modem hang.\nBecause this vulnerability resides in the baseband processor's firmware, it operates beneath the primary mobile operating system. This grants the attacker a high level of control over the availability of the device's cellular network services without requiring authentication or authorization from the device user. The exploitation is silent, meaning no indicators or prompts are displayed on the device UI, as the impact occurs at the firmware layer, rendering the modem unresponsive or requiring a full system reboot.\nAffected identifiers include Patch ID MOLY01864925 and MOLY01210562, categorized under Issue ID MSV-8303. The exploit does not require prior execution privileges, as the modem parses network-supplied data in an inherently privileged execution context relative to the baseband operating system."
}
CVE-2026-20527: Modem Missing Bounds Check Crash (MEDIUM Severity, CVSS: 5.3) | Sceawere