CVE-2026-20450Active Exploitation(mediatek / mt2735)

MEDIUMCVSS 6.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for mediatek mt2735 systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01753620; Issue ID: MSV-6100.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-617

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mt2735
  • mt2735_firmware
  • mt2737
  • mt2737_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • 3 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
mt2735mt2735_firmwaremt2737mt2737_firmwaremt6833mt6833_firmwaremt6835mt6835_firmwaremt6853mt6853_firmware

1 version affected across 102 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-04: 3Active Exploitation · 2026-05-04: 1Technical Details · 2026-05-04: 205-04
Signal classification3 categories
Active Exploitation
133.3%
Disclosure
133.3%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-20450 In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station… https://www.cve.org/CVERecord?id=CVE-2026-20450

    Post summary

    The short notice announces CVE‑2026‑20450, noting that incorrect error handling could cause a system crash and remote denial of service when an UE connects to a rogue base station, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00010174
    57.4K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    Our CTI team identified a lot of activities targeting MediaTek MT2735 and other products (CVE-2026-20450) https://vuldb.com/vuln/360940/cti

    Post summary

    CTI analysts reported multiple attack activities targeting the MediaTek MT2735 product line linked to CVE‑2026‑20450, indicating that the vulnerability is likely being exploited in the wild.

    0000047
    2.1K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-20450 Remote Denial of Service in Modem via Incorrect Error Handling https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-20450

    Post summary

    The entry references CVE-2026-20450, describing it as a remote denial‑of‑service flaw due to incorrect error handling, but offers no additional information such as PoC, exploit code, or patch details.

    0000060
    4.0K followersView on X
CPE platform detail102 entries

102 of 102 entries

PartVendorProductVersionTarget SWTarget HW
HWmediatekmt2735---
OSmediatekmt2735_firmware---
HWmediatekmt2737---
OSmediatekmt2737_firmware---
HWmediatekmt6833---
OSmediatekmt6833_firmware---
HWmediatekmt6835---
OSmediatekmt6835_firmware---
HWmediatekmt6853---
OSmediatekmt6853_firmware---
HWmediatekmt6855---
OSmediatekmt6855_firmware---
HWmediatekmt6858---
OSmediatekmt6858_firmware---
HWmediatekmt6873---
OSmediatekmt6873_firmware---
HWmediatekmt6875---
OSmediatekmt6875_firmware---
HWmediatekmt6877---
OSmediatekmt6877_firmware---
HWmediatekmt6878---
OSmediatekmt6878_firmware---
HWmediatekmt6879---
OSmediatekmt6879_firmware---
HWmediatekmt6880---
OSmediatekmt6880_firmware---
HWmediatekmt6883---
OSmediatekmt6883_firmware---
HWmediatekmt6885---
OSmediatekmt6885_firmware---
HWmediatekmt6886---
OSmediatekmt6886_firmware---
HWmediatekmt6889---
OSmediatekmt6889_firmware---
HWmediatekmt6890---
OSmediatekmt6890_firmware---
HWmediatekmt6891---
OSmediatekmt6891_firmware---
HWmediatekmt6893---
OSmediatekmt6893_firmware---
HWmediatekmt6895---
OSmediatekmt6895_firmware---
HWmediatekmt6896---
OSmediatekmt6896_firmware---
HWmediatekmt6897---
OSmediatekmt6897_firmware---
HWmediatekmt6899---
OSmediatekmt6899_firmware---
HWmediatekmt6980---
OSmediatekmt6980_firmware---
HWmediatekmt6983---
OSmediatekmt6983_firmware---
HWmediatekmt6985---
OSmediatekmt6985_firmware---
HWmediatekmt6986---
OSmediatekmt6986_firmware---
HWmediatekmt6989---
OSmediatekmt6989_firmware---
HWmediatekmt6990---
OSmediatekmt6990_firmware---
HWmediatekmt6991---
OSmediatekmt6991_firmware---
HWmediatekmt6993---
OSmediatekmt6993_firmware---
HWmediatekmt8668---
OSmediatekmt8668_firmware---
HWmediatekmt8673---
OSmediatekmt8673_firmware---
HWmediatekmt8675---
OSmediatekmt8675_firmware---
HWmediatekmt8676---
OSmediatekmt8676_firmware---
HWmediatekmt8678---
OSmediatekmt8678_firmware---
HWmediatekmt8755---
OSmediatekmt8755_firmware---
HWmediatekmt8771---
OSmediatekmt8771_firmware---
HWmediatekmt8775---
OSmediatekmt8775_firmware---
HWmediatekmt8791---
OSmediatekmt8791_firmware---
HWmediatekmt8791t---
OSmediatekmt8791t_firmware---
HWmediatekmt8792---
OSmediatekmt8792_firmware---
HWmediatekmt8793---
OSmediatekmt8793_firmware---
HWmediatekmt8795t---
OSmediatekmt8795t_firmware---
HWmediatekmt8797---
OSmediatekmt8797_firmware---
HWmediatekmt8798---
OSmediatekmt8798_firmware---
HWmediatekmt8863---
OSmediatekmt8863_firmware---
HWmediatekmt8873---
OSmediatekmt8873_firmware---
HWmediatekmt8883---
OSmediatekmt8883_firmware---
HWmediatekmt8893---
OSmediatekmt8893_firmware---

Explore more