Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-20459

CVE-2026-20459: Modem DOS Vulnerability via Rogue Station

CVE-2026-20459 is a denial of service flaw in Modem that enables system crashes through rogue base stations. This article covers the technical details, affected versions, impact, and mitigation strategies.

Published:

CVE-2026-20459 Overview

CVE-2026-20459 is an improper input validation vulnerability [CWE-288] in MediaTek Modem firmware. The flaw allows a remote attacker to trigger a system crash on a User Equipment (UE) device after the UE connects to a rogue base station under attacker control. Exploitation requires no user interaction and no additional execution privileges. The result is a remote denial of service on the affected mobile device. MediaTek tracks the fix under Patch ID MOLY01816800 and Issue ID MSV-6842.

Critical Impact

A rogue base station operator within radio range can crash the modem of any connected UE, disrupting cellular connectivity without authentication or user interaction.

Affected Products

  • MediaTek Modem firmware (Patch ID MOLY01816800)
  • Mobile devices using vulnerable MediaTek baseband chipsets
  • Devices identified under Issue ID MSV-6842 in the MediaTek July 2026 bulletin

Discovery Timeline

  • 2026-07-01 - CVE-2026-20459 published to NVD
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-20459

Vulnerability Analysis

The vulnerability resides in the MediaTek Modem firmware and stems from improper validation of input received from a base station. When the UE processes malformed data delivered over the cellular air interface, the modem enters a fault state and crashes. The attack vector is adjacent network, meaning the adversary must be within radio range of the target and operate a rogue base station that the UE connects to. Because cellular UEs may attach to base stations before mutual authentication completes on certain control-plane messages, an attacker can inject malicious input during early attach or signaling exchanges. The impact is limited to availability. Confidentiality and integrity remain unaffected according to the published CVSS vector, but sustained abuse can produce persistent connectivity loss for affected handsets.

Root Cause

The root cause is improper input validation categorized as [CWE-288] Authentication Bypass Using an Alternate Path or Channel in the NVD record, combined with unchecked parsing of attacker-controlled fields from the radio link. The modem accepts and processes crafted signaling data without sufficient bounds or state checks, leading to an unrecoverable error condition.

Attack Vector

Exploitation requires the attacker to stand up a rogue base station broadcasting on frequencies the target UE will attempt to attach to. Once the UE camps on the rogue cell, the attacker transmits malformed signaling that the modem fails to validate, producing a crash. No credentials, prior compromise, or user action are required. See the MediaTek Product Security Bulletin for vendor-supplied technical context.

No public proof-of-concept code is available for CVE-2026-20459. The vulnerability manifests during signaling processing in the baseband stack and is described only at the level provided in the MediaTek bulletin.

Detection Methods for CVE-2026-20459

Indicators of Compromise

  • Unexpected modem resets, radio subsystem restarts, or repeated loss of cellular service on MediaTek-based devices
  • Kernel or rild log entries indicating baseband crash dumps or ramdump collection events
  • Devices attaching to unknown or unauthenticated cells with anomalous PLMN, TAC, or cell ID values

Detection Strategies

  • Correlate device telemetry for repeated baseband crash and reattach cycles across a fleet, which may indicate a nearby rogue base station
  • Monitor MDM or EMM platforms for cellular connectivity failure events clustered by geography or time
  • Use wireless survey tools to detect unauthorized cells operating on carrier frequencies in sensitive locations

Monitoring Recommendations

  • Ingest mobile device crash and connectivity logs into a centralized analytics platform for pattern analysis
  • Track modem firmware versions across managed devices to confirm patch coverage against Patch ID MOLY01816800
  • Flag any device reporting frequent modem restarts for further investigation and physical location correlation

How to Mitigate CVE-2026-20459

Immediate Actions Required

  • Apply the MediaTek July 2026 security patch containing fix MOLY01816800 as soon as it is available from the device OEM
  • Inventory MediaTek-based devices in the environment and prioritize patch deployment for high-value users
  • Instruct users in sensitive roles to avoid unknown or low-signal cellular environments until patches are applied

Patch Information

MediaTek has issued a fix under Patch ID MOLY01816800, tracked as Issue ID MSV-6842, and published in the MediaTek Product Security Bulletin - July 2026. Device OEMs incorporate this patch into their monthly security updates. Consult the specific handset vendor for the corresponding firmware release.

Workarounds

  • Where supported, restrict devices to 5G or LTE-only modes to reduce exposure to downgrade attacks from rogue base stations
  • Enable carrier features such as strict PLMN allow-lists on managed devices when available
  • For high-risk users, use enterprise mobile threat defense agents that can alert on suspicious cellular network behavior

No generic configuration snippet applies. Mitigation is achieved through OEM firmware updates that include Patch ID MOLY01816800.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.