MediaTek Modem Component Remote Denial-of-Service Vulnerability

Vulnerability

A denial-of-service vulnerability has been identified in the modem component of various MediaTek chipsets, including MT2735, MT6833, MT6853, MT6855, MT6873, MT6875, MT6877, MT6880, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, and MT8791. The issue arises from improper input validation, which can lead to a system crash. Exploitation of this vulnerability is possible when a user equipment (UE) device is connected to a rogue base station controlled by an attacker. Notably, no additional execution privileges are required for exploitation, and user interaction is not needed.

Impact

Exploitation of this vulnerability can cause a system crash, leading to a remote denial-of-service condition.

Remediation

MediaTek has issued a patch for this vulnerability, which can be applied by device manufacturers. The patch ID is MOLY01738293.

Added: Feb 2, 2026, 9:20 AM
Updated: Feb 2, 2026, 9:20 AM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
4.3
remediation
0.0
relevance
2.4
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.