CVE-2026-20421: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01738293; Issue ID: MSV-5922.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20421?
The severity of CVE-2026-20421 is considered moderate due to its potential to cause remote denial of service.
How do I fix CVE-2026-20421?
To fix CVE-2026-20421, apply the latest security patch provided by MediaTek.
What systems are affected by CVE-2026-20421?
CVE-2026-20421 affects MediaTek NR15 modem systems connected to rogue base stations.
Is user interaction required to exploit CVE-2026-20421?
No, user interaction is not needed to exploit CVE-2026-20421.
What could happen if CVE-2026-20421 is exploited?
Exploitation of CVE-2026-20421 could lead to a system crash resulting in a remote denial of service.