CVE-2026-20403: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689254 (Note: For N15 and NR16) / MOLY01689259 (Note: For NR17 and NR17R); Issue ID: MSV-4843.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20403?
CVE-2026-20403 is classified as a high severity vulnerability due to its potential to cause a remote denial of service.
How do I fix CVE-2026-20403?
To fix CVE-2026-20403, apply the latest security patch provided by MediaTek for the affected modem versions.
What specific devices are affected by CVE-2026-20403?
CVE-2026-20403 affects MediaTek NR15, NR16, NR17, and NR17r modems.
Can CVE-2026-20403 be exploited without user interaction?
Yes, CVE-2026-20403 can be exploited remotely without any user interaction required.
What are the potential consequences of CVE-2026-20403?
The potential consequence of CVE-2026-20403 is a system crash leading to a denial of service for connected devices.