Answer in brief
CVE-2026-20504 records a Unknown severity vulnerability in CISA ADP Vulnrichment. The current sources do not mark it as known exploited. The current feed maps MediaTek, Inc./MediaTek chipset (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps MediaTek, Inc./MediaTek chipset (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| MediaTek, Inc./MediaTek chipsetgeneric | MT2735 || MT6833 || MT6853 || MT6855 || MT6873 || MT6875 || MT6877 || MT6880 || MT6883 || MT6885 || MT6889 || MT6890 || MT6891 || MT6893 || MT8675 || MT8771 || MT8791 || MT8791T || MT8797 | Not reported |
Published upstream
Sep 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 7, 2026
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00755024; Issue ID: MSV-7865.
Quoted source text, attributed separately from HOL analysis.