CVE-2026-20406: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01726634; Issue ID: MSV-5728.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20406?
CVE-2026-20406 has a medium severity rating due to its potential to cause a remote denial of service.
How do I fix CVE-2026-20406?
To fix CVE-2026-20406, apply the relevant patches provided by MediaTek for affected versions.
Who is affected by CVE-2026-20406?
CVE-2026-20406 affects MediaTek NR15, NR16, NR17, and NR17R models connecting to rogue base stations.
What type of vulnerability is CVE-2026-20406?
CVE-2026-20406 is categorized as a denial of service vulnerability due to an uncaught exception.
Is user interaction required to exploit CVE-2026-20406?
No, user interaction is not required to exploit CVE-2026-20406, making it a more serious threat.