CVE-2026-20401: High severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738310; Issue ID: MSV-5933.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20401?
CVE-2026-20401 is a critical vulnerability that can lead to a remote denial of service due to an uncaught exception in the Modem.
How can I fix CVE-2026-20401?
To fix CVE-2026-20401, you need to apply the latest patch provided by MediaTek as indicated in their security bulletin.
What systems are affected by CVE-2026-20401?
CVE-2026-20401 affects MediaTek NR15 Modem systems that connect to rogue base stations.
Can CVE-2026-20401 be exploited without user interaction?
Yes, CVE-2026-20401 can be exploited remotely without any user interaction required.
What are the potential consequences of CVE-2026-20401?
The potential consequences of CVE-2026-20401 include system crashes and remote denial of service when targeted by an attacker.