cbcvebase.
CVE-2026-20403
published 2026-02-02

CVE-2026-20403: In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base…

PriorityP429medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.22%
12.1th percentile
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note: For N15 and NR16) / MOLY01689259 (Note: For NR17 and NR17R); Issue ID: MSV-4843.

Affected

42 ranges· showing 25
VendorProductVersion rangeFixed in
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
mediatek_incmediatek_chipset
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.