216.73.217.172

CVE-2026-20421

· Published 02/02/2026 09:15 · Modified 03/02/2026 21:23

Labels: CVE-2026-20421 2026-02-02CVE-2026-20421CWE-125[email protected]

Essential information

Published
02/02/2026 09:15
Modified
03/02/2026 21:23
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738293; Issue ID: MSV-5922.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
mediatek / nr15 cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:*
mediatek / mt2735 cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
mediatek / mt6833 cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
mediatek / mt6853 cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
mediatek / mt6855 cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
mediatek / mt6873 cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
mediatek / mt6875 cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
mediatek / mt6877 cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
mediatek / mt6880 cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
mediatek / mt6883 cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
mediatek / mt6885 cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
mediatek / mt6889 cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
mediatek / mt6890 cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
mediatek / mt6891 cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
mediatek / mt6893 cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
mediatek / mt8791 cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*

References