MinorCritical vulnerability
CVE-2026-20520 (CVSS 7.5)
NVD · officialPublished Oct 5, 2026Risk 23/100EPSS 0.2%
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01778988; Issue ID: MSV-8897.
Technical details
CVSS
7.5
AV:Adjacent NetworkAC:HighPR:NoneUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source