Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-20503

Quick assessment

Affected
MediaTek, Inc. MediaTek chipset
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Modem(调制解调器)模块中,由于缺少边界检查,可能导致系统崩溃。如果用户设备(UE)连接到由攻击者控制的恶意基站,则可能引发远程拒绝服务(DoS)攻击。利用此漏洞无需额外的执行权限,且不需要用户交互即可触发。补丁编号:MOLY01371002;问题编号:MSV-9020。

AI Predicted 7.5 Difficulty: Moderate
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-20503

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01371002; Issue ID: MSV-9020.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
可达断言
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MediaTek, Inc. MediaTek chipset MT2716 -

II. Public POCs for CVE-2026-20503

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-20503

登录查看更多情报信息。

Vendor Advisories for CVE-2026-20503 (1)

Same Patch Batch · MediaTek, Inc. · 2026-09-07 · 18 CVEs total

CVE-2026-20509 Power HAL越界写导致本地提权
CVE-2026-20500 Modem 输入验证不当致本地拒绝服务
CVE-2026-20501 vdec堆缓冲区溢出:本地提权
CVE-2026-20502 vdec 缓冲区越界写导致本地提权
CVE-2026-20504 Modem缺失边界检查导致远程拒绝服务
CVE-2026-20516 MiracastService 权限提升漏洞
CVE-2026-20506 Audio HAL UAF 本地权限提升漏洞
CVE-2026-20507 Audio HAL:系统权限下use after free提权漏洞
CVE-2026-20508 Power HAL 类型混淆致本地提权漏洞
CVE-2026-20518 geniezone 越界检查缺失致信息泄露
CVE-2026-20510 相机中间件双重重用致本地提权
CVE-2026-20511 SurfaceFlinger 内存破坏(Use-After-Free)致本地提权
CVE-2026-20512 Audio HAL权限提升漏洞
CVE-2026-20513 Audio HAL信息泄露:System权限下本地信息暴露
CVE-2026-20514 Audio HAL 信息泄露:缺少权限检查
CVE-2026-20515 GPU系统因释放后使用致崩溃并泄露信息
CVE-2026-20517 GenieZone 系统权限提升漏洞(UAF)

IV. Related Vulnerabilities

V. Comments for CVE-2026-20503

No comments yet


Leave a comment