CVE-2024-20131Active Exploitation(mediatek / mt2737)

MEDIUMCVSS 6.7 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch mediatek mt2737 systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

In Modem, there is a possible escalation of privilege due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01395886; Issue ID: MSV-1873.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mt2737
  • mt2739
  • mt6789
  • mt6813

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mt2737mt2739mt6789mt6813mt6815mt6835mt6835tmt6855mt6878mt6878t

1 version affected across 33 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-23: 1Active Exploitation · 2026-03-23: 1Patch / Workaround · 2026-03-23: 103-23
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • NCX Group Security@ncxgroup
    Active Exploitation

    CISA just ordered a 3-day turnaround for agencies to patch a critical Cisco firewall flaw (CVE-2024-20131). Ransomware groups are actively exploiting it. Cyber risk is business risk—ask your IT team if your systems are patched today. Don't wait for downtime. https://f.mtr.cool/ffztydxguc

    Post summary

    CISA has mandated a rapid patch for CVE-2024-20131, citing active exploitation by ransomware groups.

    0000069
    9.9K followersView on X
CPE platform detail33 entries

33 of 33 entries

PartVendorProductVersionTarget SWTarget HW
HWmediatekmt2737---
HWmediatekmt2739---
HWmediatekmt6789---
HWmediatekmt6813---
HWmediatekmt6815---
HWmediatekmt6835---
HWmediatekmt6835t---
HWmediatekmt6855---
HWmediatekmt6878---
HWmediatekmt6878t---
HWmediatekmt6879---
HWmediatekmt6886---
HWmediatekmt6895---
HWmediatekmt6895t---
HWmediatekmt6896---
HWmediatekmt6897---
HWmediatekmt6899---
HWmediatekmt6980---
HWmediatekmt6980d---
HWmediatekmt6983---
HWmediatekmt6985---
HWmediatekmt6986---
HWmediatekmt6986d---
HWmediatekmt6988---
HWmediatekmt6989---
HWmediatekmt6990---
HWmediatekmt6991---
HWmediatekmt8673---
HWmediatekmt8676---
HWmediatekmt8795t---
HWmediatekmt8798---
OSmediateknr16---
OSmediateknr17---

Explore more