Sceawere
Vulnerability Detail
CVE-2026-20538UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-126 Buffer Over-read
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8914.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T02:16:52.753Z",
"pubdate": "2026-10-05T02:16:52.753Z",
"executiveSummary": "This vulnerability involves an out-of-bounds (OOB) read condition within the modem firmware component, specifically identified by Issue ID MSV-8914. The flaw stems from a critical absence of appropriate permission validation logic when processing incoming data.\nThe vulnerability allows a remote attacker to trigger a denial-of-service (DoS) state on an affected User Equipment (UE). By simulating a rogue base station, an attacker can coerce the UE into processing malicious radio resource control or signaling messages. Because the modem operates at a low level within the communication stack, this exploit requires no user interaction and does not depend on elevated execution privileges on the host operating system.\nThe primary risk is the destabilization or crash of the modem subsystem, leading to a loss of connectivity. Given that the attack surface is exposed via the cellular network interface, the threat is persistent for devices operating in proximity to malicious radio infrastructure. The lack of authentication requirements at the protocol level makes this an effective vector for remote service disruption.",
"technicalDetails": "The root cause of the vulnerability is an insufficient bounds checking mechanism during the parsing of signaling data within the modem firmware. When the modem receives data structures from the base station, the logic fails to adequately verify the integrity or the defined boundaries of the provided data fields before referencing them in memory. This leads to an out-of-bounds read, where the firmware accesses memory locations outside of the allocated buffer scope.\nThe attack flow commences when a target UE initiates a connection or performs a cell reselection to an attacker-controlled rogue base station. The rogue station acts as a Man-in-the-Middle (MitM) or a malicious legitimate cell, broadcasting specifically crafted radio signaling messages. These messages are engineered to contain header fields or length identifiers that contradict the actual payload size, forcing the modem's parsing routine to read beyond the legitimate buffer boundaries.\nBecause the modem firmware typically executes in a high-privilege environment with direct access to hardware registers and shared memory, triggering an out-of-bounds read can lead to a deterministic memory fault. If the out-of-bounds read operation accesses an unmapped memory region or triggers an exception handler that is not equipped to recover from the memory violation, the modem subsystem will crash. This results in an immediate loss of cellular network capabilities (DoS).\nExploitation is facilitated by the inherent trust the modem places in signaling messages received over the air interface. Since there is no requirement for upper-layer application privileges or user-level authorization, the modem firmware is uniquely exposed. The impact is significant because the modem usually handles its own baseband processing; a crash often necessitates a firmware restart or a hardware reset, during which the device is completely disconnected from the network. No additional privileges are required beyond the ability to influence the radio environment, making the attack highly effective against susceptible UEs that attempt to camp on the malicious station's broadcast."
}