Sceawere

Vulnerability Detail

CVE-2026-20541UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Modem Out of Bounds Read

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
17h ago
Vendor
MediaTek, Inc.
Product
MediaTek chipset
Attack Type
CWE-126 Buffer Over-read
Vector String
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
HIGH

Narrative and Response

Description

In Modem, there is a possible out of bounds read due to a missing permission check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01774038; Issue ID: MSV-8911.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-10-05T02:16:53.140Z",
  "pubdate": "2026-10-05T02:16:53.140Z",
  "executiveSummary": "A critical out-of-bounds read vulnerability has been identified within the Modem component of affected mobile devices, tracked under Issue ID MSV-8911. This flaw stems from a missing permission check during the processing of network communication protocols. Consequently, a remote, unauthenticated attacker can exploit this weakness to trigger a Denial of Service (DoS) condition on the target User Equipment (UE).\nThe exploit vector requires the victim's UE to connect to a rogue base station operated and controlled by the adversary. Significantly, successful exploitation requires zero user interaction and can be executed without any prior execution privileges on the target device. The impact is a complete disruption of the modem's functionality, leading to a loss of network connectivity and potential device instability.\nThis vulnerability is addressed under Patch ID MOLY01774038, which implements the necessary validation checks to prevent unauthorized memory access. Securing these baseband components is critical as they operate at a highly privileged level within the device's architecture, making denial of service attacks highly disruptive to cellular communications.",
  "technicalDetails": "The vulnerability designated by Issue ID MSV-8911 manifests as an out-of-bounds read vulnerability situated within the Modem firmware. The root cause of this security defect is a missing permission check during the parsing or processing of incoming over-the-air (OTA) signaling messages transmitted from a base station. Specifically, when a User Equipment (UE) establishes a connection and exchanges signaling data, the Modem's baseband processor parses the incoming packets into pre-allocated memory buffers. Due to the lack of validation and missing permission controls, the parser attempts to read memory addresses outside the designated buffer boundaries when processing malformed or crafted messages.\nTo exploit this vulnerability, an attacker must deploy a rogue base station (often referred to as an IMSI catcher or malicious cell tower) within physical proximity of the target UE. The attack flow proceeds as follows: First, the attacker configures the rogue base station to broadcast cellular system information resembling a legitimate network operator to entice the target UE to connect. Second, the target UE, following standard cellular network selection protocols, initiates a connection and attaches to the rogue base station. This process requires absolutely no user interaction or confirmation. Third, once the UE is connected, the rogue base station transmits specially crafted signaling frames or radio resource control (RRC) messages containing anomalous parameters to the target UE.\nFourth, the Modem of the UE receives these frames and forwards them to the vulnerable parsing module. Fifth, because the parsing module lacks the necessary permission and boundary checks, it executes an out-of-bounds read operation, attempting to access restricted or unmapped physical memory addresses. Finally, the out-of-bounds read triggers a baseband processor exception or kernel panic within the Modem subsystem.\nSince the cellular Modem operates within a highly isolated and privileged execution environment, a crash in this subsystem immediately leads to a complete loss of cellular network capabilities, resulting in a remote Denial of Service (DoS) state. The device will be unable to make calls, send SMS messages, or utilize cellular data until the Modem subsystem is reset or the device is rebooted. The vulnerability does not require any execution privileges on the UE, nor does it require local authentication, making it an entirely remote over-the-air vector. This issue is resolved by applying Patch ID MOLY01774038, which enforces strict validation and bounds checks on all incoming network signaling data."
}
CVE-2026-20541: Modem Out of Bounds Read (MEDIUM Severity, CVSS: 5.3) | Sceawere