CVE-2026-20431Disclosure(mediatek / mt6813)

LOWCVSS 6.5 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01106496; Issue ID: MSV-4467.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mt6813
  • mt6813_firmware
  • mt6815
  • mt6815_firmware

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Disclouser: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-07); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
mt6813mt6813_firmwaremt6815mt6815_firmwaremt6835mt6835_firmwaremt6878mt6878_firmwaremt6897mt6897_firmware

1 version affected across 38 products

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-04-07: 3Mentions · 2026-04-19: 2Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 204-0704-19
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Disclouser
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-073
Disclosure2General1
2026-04-192
Disclosure1Disclouser1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-20431 In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled… https://www.cve.org/CVERecord?id=CVE-2026-20431

    Post summary

    CVE‑2026‑20431 describes a logic error that may trigger a remote denial of service via a rogue base station, but no PoC, exploit, patch, or active exploitation is reported.

    00010750
    57.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclouser

    🚨*CVE* CVE-2026-20431 In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled… https://www.cve.org/CVERecord?id=CVE-2026-20431 ----- Traducción: CVE-2026-20431 En … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-20431, describing a logic error that could lead to remote denial of service via rogue base stations, and provides a link to the CVE record for further details.

    0000043
    72 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-20431 Remote Denial of Service via Logic Error in Modem System ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20431 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The post announces CVE-2026-20431 as a remote DoS vulnerability caused by a logic error in modem systems, linking to details but lacking PoC, exploit, or patch information.

    0000049
    4.0K followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-20431 🚨 Risk Level: Unknown 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-20431 #CVE-2026-20431 #CVE #CyberSecurity #InfoSec https://t.co/JowbhJkvpI

    Post summary

    The tweet simply announces CVE-2026-20431 with no additional details, proof of concept, active exploitation or mitigation information.

    0000030
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-20431 - "Modem Remote Denial of Service Vulnerability" Intel Report: https://ift.tt/NId3QHk

    Post summary

    The alert announces CVE-2026-20431 as a modem remote denial‑of‑service vulnerability, linking to an Intel report. No PoC, exploit code, patch, or active exploitation details are provided.

    0000033
    281 followersView on X
CPE platform detail38 entries

38 of 38 entries

PartVendorProductVersionTarget SWTarget HW
HWmediatekmt6813---
OSmediatekmt6813_firmware---
HWmediatekmt6815---
OSmediatekmt6815_firmware---
HWmediatekmt6835---
OSmediatekmt6835_firmware---
HWmediatekmt6878---
OSmediatekmt6878_firmware---
HWmediatekmt6897---
OSmediatekmt6897_firmware---
HWmediatekmt6899---
OSmediatekmt6899_firmware---
HWmediatekmt6986---
OSmediatekmt6986_firmware---
HWmediatekmt6991---
OSmediatekmt6991_firmware---
HWmediatekmt6993---
OSmediatekmt6993_firmware---
HWmediatekmt8668---
OSmediatekmt8668_firmware---
HWmediatekmt8676---
OSmediatekmt8676_firmware---
HWmediatekmt8678---
OSmediatekmt8678_firmware---
HWmediatekmt8755---
OSmediatekmt8755_firmware---
HWmediatekmt8775---
OSmediatekmt8775_firmware---
HWmediatekmt8792---
OSmediatekmt8792_firmware---
HWmediatekmt8793---
OSmediatekmt8793_firmware---
HWmediatekmt8863---
OSmediatekmt8863_firmware---
HWmediatekmt8873---
OSmediatekmt8873_firmware---
HWmediatekmt8883---
OSmediatekmt8883_firmware---

Explore more