Sceawere
Vulnerability Detail
CVE-2026-20543UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Modem Logic Error Information Disclosure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 17h ago
- Vendor
- MediaTek, Inc.
- Product
- MediaTek chipset
- Attack Type
- CWE-215 Insertion of Sensitive Information Into Debugging Code
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
In Modem, there is a possible information disclosure due to a logic error. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01645293; Issue ID: MSV-6761.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-05T02:16:53.410Z",
"pubdate": "2026-10-05T02:16:53.410Z",
"executiveSummary": "A logic error vulnerability has been identified within the Modem component, potentially allowing for the unauthorized disclosure of sensitive information.\nThis vulnerability is classified as an information disclosure issue stemming from flawed logic processing within the system.\nThe flaw affects the Modem subsystem, posing significant risks regarding the confidentiality of data processed or handled by the modem firmware.\nA local attacker can exploit this vulnerability without the requirement for elevated execution privileges or user interaction, significantly lowering the barrier to entry for potential adversaries.\nThe primary risk implication is the potential leakage of sensitive system data or information handled by the modem, which could be leveraged to facilitate further exploitation or gain unauthorized insights into the device's operational state.\nSuccessful exploitation allows an attacker to bypass standard security boundaries governing access to modem-specific information.",
"technicalDetails": "The vulnerability originates from a logic error within the Modem firmware's processing routines, specifically impacting how the component manages access control or internal state transitions when handling specific requests or system conditions.\nThe root cause appears to be an inadequate validation of internal states or parameters, which leads the Modem component to inadvertently expose information that should otherwise be protected from unprivileged access.\nThe exploitation path requires the attacker to have local access to the system. Since the vulnerability does not require additional execution privileges or user interaction, an adversary can trigger the issue by interacting with the Modem interface directly from an unprivileged context.\nOnce the logic is triggered through specifically crafted inputs or sequences that leverage the flawed processing routine, the Modem may return data that resides in memory or restricted buffers intended only for authorized internal processes.\nThe attack flow proceeds as follows: 1) The attacker initiates communication with the target Modem component. 2) The attacker submits a series of inputs designed to traverse the flawed logical branch. 3) The logic error forces the Modem to process these inputs in an insecure state. 4) The modem component returns sensitive information in the response, which is then captured by the attacker. 5) This data can then be analyzed for further intelligence or exploitation opportunities.\nBecause this vulnerability resides in the Modem, which often functions at a lower abstraction layer than the primary OS kernel, the information disclosed could include device-specific identifiers, memory addresses, or raw data streams that provide deep visibility into system operations.\nAffected components are limited to the Modem firmware as identified by Issue ID MSV-6761. No network exposure is explicitly required, as the attack is locally vectorable, though it remains a critical issue for local security posture."
}