CVE-2026-20422: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00827332; Issue ID: MSV-5919.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20422?
CVE-2026-20422 is classified as a high severity vulnerability due to its potential for causing remote denial of service.
How do I fix CVE-2026-20422?
To address CVE-2026-20422, users should apply the latest security patch provided by MediaTek for the affected devices.
What causes CVE-2026-20422?
CVE-2026-20422 is caused by improper input validation in the modem, which may lead to a system crash.
Who is affected by CVE-2026-20422?
Devices running impacted versions of MediaTek NR15, NR16, NR17, and NR17R modems are vulnerable to CVE-2026-20422.
Is user interaction required to exploit CVE-2026-20422?
No, user interaction is not required for the exploitation of CVE-2026-20422.