CVE-2026-20434: High severity MediaTek Lr12a vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY00782946; Issue ID: MSV-4135.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20434?
CVE-2026-20434 is classified as a medium severity vulnerability due to its potential for remote escalation of privilege.
How do I fix CVE-2026-20434?
To fix CVE-2026-20434, update the firmware of any affected MediaTek devices as specified in the vendor's security bulletin.
What are the exploit requirements for CVE-2026-20434?
Exploitation of CVE-2026-20434 requires user interaction and a connection to a rogue base station.
Which devices are affected by CVE-2026-20434?
CVE-2026-20434 affects several MediaTek modem models, including MediaTek Lr12a, Lr13, Nr15, Nr16, and Nr17.
Can CVE-2026-20434 lead to data breaches?
Yes, if successfully exploited, CVE-2026-20434 could facilitate unauthorized access to sensitive information.