MediaTek Modem: Improper Input Validation Causing Local DoS
CVE-2026-20500 Published on September 7, 2026
In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.
Vulnerability Analysis
CVE-2026-20500 is exploitable with local system access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Improper Certificate Validation
The software does not validate, or incorrectly validates, a certificate. When a certificate is invalid or malicious, it might allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. The software might connect to a malicious host while believing it is a trusted host, or the software might be deceived into accepting spoofed data that appears to originate from a trusted host.
Products Associated with CVE-2026-20500
Want to know whenever a new CVE is published for Google Android? stack.watch will email you.
Affected Versions
MediaTek, Inc. MediaTek chipset:- Version MT2716 is affected.
- Version MT6835 is affected.
- Version MT6858 is affected.
- Version MT6878 is affected.
- Version MT6881 is affected.
- Version MT6897 is affected.
- Version MT6899 is affected.
- Version MT6982VB is affected.
- Version MT6986 is affected.
- Version MT6988 is affected.
- Version MT6991 is affected.
- Version MT6993 is affected.
- Version MT8668 is affected.
- Version MT8676 is affected.
- Version MT8678 is affected.
- Version MT8755 is affected.
- Version MT8775 is affected.
- Version MT8792 is affected.
- Version MT8793 is affected.
- Version MT8863 is affected.
- Version MT8873 is affected.
- Version MT8883 is affected.