CVE-2026-20433: High severity MediaTek Mt2735 Firmware vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20433?
CVE-2026-20433 has a high severity rating due to its potential for remote escalation of privilege.
How do I fix CVE-2026-20433?
To fix CVE-2026-20433, ensure that you are using the latest firmware version provided by MediaTek that addresses this vulnerability.
What are the potential impacts of CVE-2026-20433?
The potential impacts of CVE-2026-20433 include unauthorized access and privilege escalation when connected to a rogue base station.
Who is affected by CVE-2026-20433?
Devices utilizing certain MediaTek firmware versions are affected by CVE-2026-20433.
Is user interaction required to exploit CVE-2026-20433?
Yes, user interaction is needed for the exploitation of CVE-2026-20433.