CVE-2026-20402: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00693083; Issue ID: MSV-5928.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20402?
CVE-2026-20402 has a high severity rating due to the potential for remote denial of service.
How do I fix CVE-2026-20402?
To address CVE-2026-20402, apply the latest security patches provided by MediaTek.
Who is affected by CVE-2026-20402?
CVE-2026-20402 affects devices using MediaTek's NR15 modem.
What are the consequences of CVE-2026-20402?
Exploiting CVE-2026-20402 can lead to a system crash and loss of service for users connected to a rogue base station.
Is user interaction required to exploit CVE-2026-20402?
No, CVE-2026-20402 can be exploited without any user interaction.