CVE-2026-20525: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01870473 / MOLY00814393; Issue ID: MSV-9041.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01870473 / MOLY00814393
Event History
Frequently Asked Questions
What must an attacker control to exploit this issue?
The attacker must operate or control a rogue base station and have a UE connect to it. No additional execution privileges or user interaction are required.
What is the likely impact on an affected device?
Successful exploitation can cause a system crash, resulting in remote denial of service.
How can organizations identify the relevant vendor remediation?
The vendor identifies the fixes with Patch IDs MOLY01870473 and MOLY00814393, and tracks the issue as MSV-9041.