CVE-2026-20432: High severity MediaTek Mt2735 Firmware vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01406170; Issue ID: MSV-4461.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01406170
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20432?
CVE-2026-20432 has a high severity rating due to its potential for remote escalation of privilege.
How do I fix CVE-2026-20432?
To fix CVE-2026-20432, you should apply the latest firmware updates from MediaTek that address this vulnerability.
What types of devices are affected by CVE-2026-20432?
CVE-2026-20432 affects several MediaTek firmware including MT2735, MT2737, MT6779, and others.
What are the potential consequences of exploiting CVE-2026-20432?
Exploitation of CVE-2026-20432 could lead to unauthorized access and control over the affected device.
Is user interaction required to exploit CVE-2026-20432?
Yes, user interaction is required for the exploitation of CVE-2026-20432, typically in the form of connecting to a rogue base station.