CVE-2026-20431: Medium severity MediaTek Mt6813 Firmware vulnerability
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01106496 - Compensating control
Mitigate remote denial of service risk by preventing UEs from connecting to rogue base stations (e.g., restrict/validate allowed base stations and protect radio/network access accordingly).
- Compensating control
Because exploitation requires no user interaction, monitor for modem-related crashes/system instability and isolate affected UE/network segments if unexpected system crashes occur.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20431?
CVE-2026-20431 has the potential for remote denial of service, indicating it is a significant vulnerability.
How do I fix CVE-2026-20431?
To address CVE-2026-20431, apply the patch identified as MOLY01106 provided by MediaTek.
What are the potential impacts of CVE-2026-20431?
The impact of CVE-2026-20431 includes the possibility of a system crash when connected to a malicious base station.
Is user interaction required to exploit CVE-2026-20431?
No, user interaction is not needed for the exploitation of CVE-2026-20431.
Which devices are affected by CVE-2026-20431?
CVE-2026-20431 affects various MediaTek MT6813, MT6815, MT6835, and other firmware versions.