CVE-2026-20404: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689248; Issue ID: MSV-4837.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20404?
CVE-2026-20404 has a high severity as it can lead to a remote denial of service due to improper input validation.
How do I fix CVE-2026-20404?
To fix CVE-2026-20404, you need to apply the latest security patch provided by MediaTek for the affected software versions.
Which devices are affected by CVE-2026-20404?
CVE-2026-20404 affects MediaTek NR15, NR16, NR17, and NR17R devices due to improper input validation.
Can CVE-2026-20404 be exploited without user interaction?
Yes, CVE-2026-20404 can be exploited without user interaction if a user equipment connects to a rogue base station controlled by an attacker.
What are the potential impacts of CVE-2026-20404?
The potential impact of CVE-2026-20404 includes system crashes and remote denial of service, affecting the device's availability.