PT-2026-104679 · Mediatek · Mediatek Modem

CVE-2026-20519

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v3.1

7.5

High

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MediaTek Modem (affected versions not specified)
Description A missing bounds check in the modem allows for an out-of-bounds write. This issue can be exploited if a User Equipment (UE) connects to a rogue base station controlled by an attacker, potentially leading to remote escalation of privilege without requiring user interaction or additional execution privileges.
Recommendations Update the modem software to the version provided in the October 2026 security bulletin.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-20519

Affected Products

Mediatek Modem