VDB

CVE-2026-20433

CVE-2026-20433 PUBLISHED

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01088681; Issue ID: MSV-4460.

EPSS 0.03% · 7.5th percentile

Risk Scores

EPSS Score
0.03%
7.5th percentile

Affected Products

VendorProductVersions
MediaTek, Inc.MediaTek chipsetMT2735, MT2737, MT6813

Timeline

  • Apr 7, 2026 CVE Published
  • Apr 7, 2026 PoC Published
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
  • May 27, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›