CVE-2026-20433 is an out-of-bounds write vulnerability in Modem caused by a missing bounds check that could enable remote privilege escalation if a device connects to an attacker-controlled rogue base station. No additional execution privileges are required for exploitation, though user interaction is necessary. The vulnerability carries a CVSS score of 8.8 (HIGH) with an adjacent network attack vector, low complexity, and no privilege requirements. Successful exploitation could result in complete compromise of confidentiality, integrity, and availability on affected systems. There is currently no evidence of active exploitation in the wild, with no known public exploits available and the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog. The EPSS score of 0.00023 indicates very low probability of exploitation relative to other CVEs, and the vulnerability remains on an inactive hot list, suggesting minimal community attention at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:mt2735_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:mt2737_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:mt6813_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:mt6833_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:mediatek:mt6833p_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.