Total
14 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-20503 | 1 Mediatek | 114 Mt2716, Mt2716 Firmware, Mt2735 and 111 more | 2026-09-09 | N/A | 5.3 MEDIUM |
| In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020. | |||||
| CVE-2026-20502 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9196. | |||||
| CVE-2026-20501 | 1 Mediatek | 106 Mt2718, Mt2718 Firmware, Mt6580 and 103 more | 2026-09-09 | N/A | 8.4 HIGH |
| In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11262030; Issue ID: MSV-9197. | |||||
| CVE-2026-20483 | 1 Mediatek | 70 Mt6739, Mt6739 Firmware, Mt6761 and 67 more | 2026-08-19 | N/A | 7.7 HIGH |
| In Telephony, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS11087526; Issue ID: MSV-8243. | |||||
| CVE-2026-20484 | 1 Mediatek | 78 Mt6739, Mt6739 Firmware, Mt6761 and 75 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11053160; Issue ID: MSV-8004. | |||||
| CVE-2026-20496 | 1 Mediatek | 34 Mt6983, Mt6983 Firmware, Mt8676 and 31 more | 2026-08-19 | N/A | 4.4 MEDIUM |
| In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS11036877; Issue ID: MSV-7132. | |||||
| CVE-2026-20432 | 1 Mediatek | 116 Mt2735, Mt2735 Firmware, Mt2737 and 113 more | 2026-07-24 | N/A | 8.0 HIGH |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461. | |||||
| CVE-2026-20454 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 6.4 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6786. | |||||
| CVE-2026-20453 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 6.7 MEDIUM |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10886526; Issue ID: MSV-6791. | |||||
| CVE-2026-20455 | 1 Mediatek | 72 Mt6739, Mt6739 Firmware, Mt6761 and 69 more | 2026-07-22 | N/A | 7.8 HIGH |
| In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10873936; Issue ID: MSV-6784. | |||||
| CVE-2026-20450 | 1 Mediatek | 102 Mt2735, Mt2735 Firmware, Mt2737 and 99 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100. | |||||
| CVE-2026-20449 | 1 Mediatek | 136 Mt2735, Mt2735 Firmware, Mt2737 and 133 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148. | |||||
| CVE-2026-20433 | 1 Mediatek | 124 Mt2735, Mt2735 Firmware, Mt2737 and 121 more | 2026-06-17 | N/A | 8.8 HIGH |
| In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460. | |||||
| CVE-2025-20659 | 1 Mediatek | 170 Mt2735, Mt2735 Firmware, Mt2737 and 167 more | 2026-06-17 | N/A | 6.5 MEDIUM |
| In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01519028; Issue ID: MSV-2768. | |||||
