5.3
CVE-2026-20504
- EPSS 0.19%
- Veröffentlicht 07.09.2026 01:57:18
- Zuletzt bearbeitet 09.09.2026 02:55:33
- Erkennungen
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Mt2735 Firmware Version -
Mediatek ≫ Mt6833 Firmware Version -
Mediatek ≫ Mt6853 Firmware Version -
Mediatek ≫ Mt6855 Firmware Version -
Mediatek ≫ Mt6873 Firmware Version -
Mediatek ≫ Mt6875 Firmware Version -
Mediatek ≫ Mt6877 Firmware Version -
Mediatek ≫ Mt6880 Firmware Version -
Mediatek ≫ Mt6883 Firmware Version -
Mediatek ≫ Mt6885 Firmware Version -
Mediatek ≫ Mt6889 Firmware Version -
Mediatek ≫ Mt6890 Firmware Version -
Mediatek ≫ Mt6891 Firmware Version -
Mediatek ≫ Mt6893 Firmware Version -
Mediatek ≫ Mt8675 Firmware Version -
Mediatek ≫ Mt8771 Firmware Version -
Mediatek ≫ Mt8791 Firmware Version -
Mediatek ≫ Mt8791t Firmware Version -
Mediatek ≫ Mt8797 Firmware Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.087 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.3 | 1.6 | 3.6 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-617 Reachable Assertion
The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.
https://www.mediatek.com/product-security-bulletin/September-2026