ZeroHour

Vulnerabilities

5 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-20504
In Modem, there is a possible system crash due to a missing bounds check.

In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.

NVD description · AI analysis pending
5.3<1%
  • mediatek mt2735 firmware
  • mediatek mt6833 firmware
  • mediatek mt6853 firmware
  • +1 more
CVE-2026-20500
+1 in the same advisory: …20503
In Modem, there is a possible system crash due to improper input validation.

In Modem, there is a possible system crash due to improper input validation. This could lead to local denial of service with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01810811; Issue ID: MSV-9232.

NVD description · AI analysis pending
5.5
group max
<1%
  • mediatek mt2716 firmware
  • mediatek mt6835 firmware
  • mediatek mt6858 firmware
  • +1 more
CVE-2026-20501
+1 in the same advisory: …20502
Heap buffer overflow in MediaTek vdec firmware enables local privilege escalation

CVE-2026-20501 is a heap-based buffer overflow (CWE-122) in the vdec (video decoder) component of firmware for a wide range of MediaTek chipsets, which can cause an out-of-bounds write when crafted data is processed by the decoder. A local attacker with no additional execution privileges — for example a low-privileged app or process on the device — could exploit it without any user interaction to gain elevated privileges. Affected devices are those running firmware for the listed MediaTek SoCs (MT2718, MT6580, MT6739, MT6761, MT6765, MT6768, MT6769, MT6779, MT6781, MT6785, MT6789 and MT6833), chips commonly found in budget Android smartphones, feature phones, smart TVs and other consumer/IoT hardware. There is no evidence of active exploitation: the flaw is not in CISA KEV, has an EPSS 30-day probability of about 0.1% (3rd percentile), and no public proof-of-concept is known. The fix ships via MediaTek/OEM firmware updates associated with Patch ID ALPS11262030 (Issue ID MSV-9197).

Do: Apply the fixed firmware containing MediaTek patch ALPS11262030 (Issue MSV-9197) as soon as your device OEM or carrier ships it, and check your device's chipset against the affected list in vendor security bulletins. Because exploitation requires local code execution, the practical risk before patching is limited to attackers who can already run an app or process on the device, so avoid installing untrusted apps on affected devices. Organizations managing fleets of MediaTek-based phones, TVs or IoT hardware should prioritize OEM update rollouts for the listed SoCs.

8.4<1%
  • MediaTek MT2718 firmware
  • MediaTek MT6580 firmware
  • MediaTek MT6739 firmware
  • +9 more
massTens of millions of devices globally (order-of-magnitude estimate)