CVE-2026-20431
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/04/2026
Last modified:
10/04/2026
Description
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mediatek:mt6813_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6813:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6815_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6815:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6835_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6835:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6878_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6878:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6897_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6897:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6899_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6899:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6986_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mediatek:mt6986:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mediatek:mt6991_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



