Sceawere

Vulnerability Detail

CVE-2026-20540UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Modem Out-of-Bounds Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
17h ago
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Attack Type
CWE-126 Buffer Over-read
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8912.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T02:16:53.010Z",
  "pubdate": "2026-10-05T02:16:53.010Z",
  "executiveSummary": "This vulnerability involves an out-of-bounds (OOB) read flaw located within the Modem component, identified by Issue ID MSV-8912 and Patch ID MOLY01774038.\nThe flaw stems from a critical lack of bounds checking during data processing within the modem subsystem.\nThe vulnerability allows an attacker operating a rogue base station to trigger a remote denial of service (DoS) condition on a target User Equipment (UE).\nExploitation does not require elevated execution privileges, nor does it necessitate any form of user interaction, making it a highly accessible attack vector for proximal adversaries.\nThe primary risk implication is the forced termination or instability of cellular connectivity, potentially rendering the device unresponsive or disconnected from legitimate networks.\nThe attack is contingent upon the UE establishing a connection to the malicious base station, placing the target firmly within the radio coverage area of the attacker.",
  "technicalDetails": "The root cause of this vulnerability is an improper validation of input parameters or data structures handled by the Modem firmware. When the modem processes signals or data packets received over the air interface, it fails to verify that indices or pointers used to access memory remain within the allocated buffer boundaries.\nIn a typical scenario, the Modem component expects a specific structure or payload size when communicating with a base station. When an attacker deploys a rogue base station, they can transmit malformed packets that violate these expected protocol specifications. By providing a payload that forces the firmware to read memory addresses outside of the intended buffer, the attacker causes the Modem process to access arbitrary memory regions.\nThe exploitation flow begins with the UE scanning for available cellular networks. The attacker's rogue base station advertises itself with parameters that entice the UE to perform a location update or attach procedure. Once the UE initiates the RRC (Radio Resource Control) connection, the rogue base station sends a specifically crafted sequence of protocol messages. These messages contain values designed to bypass implicit bounds checks, causing the internal processing function to perform an OOB read operation.\nBecause the modem subsystem typically operates with high privileges within the system architecture—often on dedicated hardware or within a restricted execution environment (REE)—an out-of-bounds read can lead to an immediate system crash or a hang of the modem's processor. This results in a Denial of Service (DoS) as the device loses its ability to communicate via cellular protocols.\nThe vulnerability is particularly dangerous because the attack is conducted entirely over the radio interface (OTA). No authentication between the base station and the UE is required at the initial stages of the connection establishment, allowing the exploit to be delivered before any security context or encryption is negotiated. Post-exploitation, the modem may enter a fault state that requires a physical reset of the device or a power cycle to restore normal functionality, effectively disabling the primary communication capabilities of the device until manual intervention occurs."
}
CVE-2026-20540: Modem Out-of-Bounds Read Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere