Sceawere
Vulnerability Detail
CVE-2026-20539UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.3
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-126 Buffer Over-read
- Vector String
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8913.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.3",
"pubDate": "2026-10-05T02:16:52.883Z",
"pubdate": "2026-10-05T02:16:52.883Z",
"executiveSummary": "This vulnerability is identified as an out-of-bounds (OOB) read within the Modem component, categorized as a memory safety issue. The defect arises due to insufficient validation of input bounds during data processing, which allows for unauthorized memory access. The primary impact of this vulnerability is a remote denial of service (DoS), capable of causing the modem firmware to crash, hang, or reboot, thereby disconnecting the user equipment (UE) from the cellular network.\nThe attack vector requires the target UE to establish a connection with a rogue base station controlled by a malicious actor. Because the vulnerability exists at the radio interface layer, no user interaction is required, and no additional execution privileges are necessary for successful exploitation. The vulnerability is tracked under Issue ID MSV-8913 and addressed by Patch ID MOLY01774038. The risk level is significant due to the lack of user interaction requirements and the potential for complete loss of cellular connectivity.",
"technicalDetails": "The vulnerability resides within the Modem's handling of air interface protocols. The root cause is a missing bounds check when parsing incoming network packets or signaling messages. In embedded telecommunications software, packet buffers are typically allocated with fixed dimensions; if the parsing logic fails to verify that the incoming data offset or length parameter is within the allocated buffer boundaries, the system will attempt to read memory addresses outside the intended memory region.\nThe attack flow initiates when an attacker operates a malicious base station, typically implemented using Software Defined Radio (SDR) hardware and open-source frameworks like srsRAN or Osmocom. When a victim UE enters the range of this rogue base station, it performs the standard cell selection and attachment procedures. Once the Radio Resource Control (RRC) or Non-Access Stratum (NAS) connection is established, the attacker sends a malformed or specifically crafted protocol data unit (PDU) designed to trigger the OOB read.\nUpon receiving the malicious packet, the vulnerable Modem component processes the payload using an insecure indexing operation. Because the bounds check is absent, the pointer arithmetic used to access the data fields is not constrained. The firmware attempts to read memory directly from an adjacent, unauthorized segment of the heap or stack. Depending on the memory layout and the specific offset triggered, this action leads to an immediate memory corruption event or a fault exception. In real-time embedded systems, an unhandled memory access violation typically triggers a kernel panic or a watchdog reset, causing the modem to transition into an error state or a reboot loop.\nThe exposure is strictly remote and localized to the air interface. An attacker does not require local access to the device or prior authentication. By manipulating the downlink signaling, the attacker can force the modem into an unstable state. While this OOB read is primarily described as causing a denial of service, such primitives can occasionally be leveraged in more sophisticated chains to leak sensitive information if the memory content is reflected back in subsequent signaling responses, or to bypass security features if the read facilitates a subsequent write primitive."
}