CVE-2026-20450
MEDIUMDescription
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mediatek | mt2735_firmware |
| mediatek | mt2735 |
| mediatek | mt2737_firmware |
| mediatek | mt2737 |
| mediatek | mt6833_firmware |
| mediatek | mt6833 |
| mediatek | mt6835_firmware |
| mediatek | mt6835 |
| mediatek | mt6853_firmware |
| mediatek | mt6853 |
| mediatek | mt6855_firmware |
| mediatek | mt6855 |
| mediatek | mt6858_firmware |
| mediatek | mt6858 |
| mediatek | mt6873_firmware |
| mediatek | mt6873 |
| mediatek | mt6875_firmware |
| mediatek | mt6875 |
| mediatek | mt6877_firmware |
| mediatek | mt6877 |
| mediatek | mt6878_firmware |
| mediatek | mt6878 |
| mediatek | mt6879_firmware |
| mediatek | mt6879 |
| mediatek | mt6880_firmware |
| mediatek | mt6880 |
| mediatek | mt6883_firmware |
| mediatek | mt6883 |
| mediatek | mt6885_firmware |
| mediatek | mt6885 |
| mediatek | mt6886_firmware |
| mediatek | mt6886 |
| mediatek | mt6889_firmware |
| mediatek | mt6889 |
| mediatek | mt6890_firmware |
| mediatek | mt6890 |
| mediatek | mt6891_firmware |
| mediatek | mt6891 |
| mediatek | mt6893_firmware |
| mediatek | mt6893 |
| mediatek | mt6895_firmware |
| mediatek | mt6895 |
| mediatek | mt6896_firmware |
| mediatek | mt6896 |
| mediatek | mt6897_firmware |
| mediatek | mt6897 |
| mediatek | mt6899_firmware |
| mediatek | mt6899 |
| mediatek | mt6980_firmware |
| mediatek | mt6980 |
| mediatek | mt6983_firmware |
| mediatek | mt6983 |
| mediatek | mt6985_firmware |
| mediatek | mt6985 |
| mediatek | mt6986_firmware |
| mediatek | mt6986 |
| mediatek | mt6989_firmware |
| mediatek | mt6989 |
| mediatek | mt6990_firmware |
| mediatek | mt6990 |
| mediatek | mt6991_firmware |
| mediatek | mt6991 |
| mediatek | mt6993_firmware |
| mediatek | mt6993 |
| mediatek | mt8668_firmware |
| mediatek | mt8668 |
| mediatek | mt8673_firmware |
| mediatek | mt8673 |
| mediatek | mt8675_firmware |
| mediatek | mt8675 |
| mediatek | mt8676_firmware |
| mediatek | mt8676 |
| mediatek | mt8678_firmware |
| mediatek | mt8678 |
| mediatek | mt8755_firmware |
| mediatek | mt8755 |
| mediatek | mt8771_firmware |
| mediatek | mt8771 |
| mediatek | mt8775_firmware |
| mediatek | mt8775 |
| mediatek | mt8791_firmware |
| mediatek | mt8791 |
| mediatek | mt8791t_firmware |
| mediatek | mt8791t |
| mediatek | mt8792_firmware |
| mediatek | mt8792 |
| mediatek | mt8793_firmware |
| mediatek | mt8793 |
| mediatek | mt8795t_firmware |
| mediatek | mt8795t |
| mediatek | mt8797_firmware |
| mediatek | mt8797 |
| mediatek | mt8798_firmware |
| mediatek | mt8798 |
| mediatek | mt8863_firmware |
| mediatek | mt8863 |
| mediatek | mt8873_firmware |
| mediatek | mt8873 |
| mediatek | mt8883_firmware |
| mediatek | mt8883 |
| mediatek | mt8893_firmware |
| mediatek | mt8893 |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2026-20450? +
How severe is CVE-2026-20450? +
What products are affected by CVE-2026-20450? +
How do I check if I'm vulnerable to CVE-2026-20450? +
Related Vulnerabilities
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard …
wb2osz/direwolf (Dire Wolf) versions up to and including 1.8, prior to commit 3658a87, contain a reachable assertion vulnerability in the …
In the Linux kernel, the following vulnerability has been resolved: crypto: tegra - Add missing CRYPTO_ALG_ASYNC The tegra crypto driver …
Open5GS MME versions <= 2.6.4 contains an assertion that can be remotely triggered via a malformed ASN.1 packet over the …
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the …
Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the …