MediaTek Modem Remote DoS via Rogue Base Station
CVE-2026-20431 Published on April 7, 2026
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.
Weakness Type
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Affected Versions
MediaTek, Inc. MediaTek chipset:- Version MT6813 is affected.
- Version MT6815 is affected.
- Version MT6835 is affected.
- Version MT6878 is affected.
- Version MT6897 is affected.
- Version MT6899 is affected.
- Version MT6986 is affected.
- Version MT6991 is affected.
- Version MT6993 is affected.
- Version MT8668 is affected.
- Version MT8676 is affected.
- Version MT8678 is affected.
- Version MT8755 is affected.
- Version MT8775 is affected.
- Version MT8792 is affected.
- Version MT8793 is affected.
- Version MT8863 is affected.
- Version MT8873 is affected.
- Version MT8883 is affected.