PT-2026-104679 · Mediatek · Mediatek Modem
CVE-2026-20519
·
Published
2026-10-05
·
Updated
2026-10-05
CVSS v3.1
7.5
High
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MediaTek Modem (affected versions not specified)
Description
A missing bounds check in the modem allows for an out-of-bounds write. This issue can be exploited if a User Equipment (UE) connects to a rogue base station controlled by an attacker, potentially leading to remote escalation of privilege without requiring user interaction or additional execution privileges.
Recommendations
Update the modem software to the version provided in the October 2026 security bulletin.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mediatek Modem