{"id":51211,"date":"2026-05-04T08:28:43","date_gmt":"2026-05-04T08:28:43","guid":{"rendered":"https:\/\/zero.redgem.net\/?p=51211"},"modified":"2026-05-04T08:28:43","modified_gmt":"2026-05-04T08:28:43","slug":"cve-2026-20449","status":"publish","type":"post","link":"https:\/\/zero.redgem.net\/?p=51211","title":{"rendered":"CVE-2026-20449_CVE-2026-20449"},"content":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01760138; Issue ID: MSV-6148.&#8221;,&#8221;published&#8221;:&#8221;2026-05-04T05:41:54.581Z&#8221;,&#8221;modified&#8221;:&#8221;2026-05-04T12:59:15.818Z&#8221;,&#8221;type&#8221;:&#8221;cve&#8221;,&#8221;title&#8221;:&#8221;CVE-2026-20449&#8243;,&#8221;source&#8221;:&#8221;MediaTek&#8221;,&#8221;references&#8221;:&#8221;https:\/\/corp.mediatek.com\/product-security-bulletin\/May-2026&#8243;,&#8221;id&#8221;:&#8221;CVE-2026-20449&#8243;,&#8221;bulletinFamily&#8221;:&#8221;&#8221;,&#8221;cwe&#8221;:[&#8220;CWE-120&#8243;],&#8221;cvelist&#8221;:null,&#8221;sourceData&#8221;:&#8221;MediaTek, Inc. MediaTek chipset MT2735\\nMediaTek, Inc. MediaTek chipset MT2737\\nMediaTek, Inc. MediaTek chipset MT6739\\nMediaTek, Inc. MediaTek chipset MT6761\\nMediaTek, Inc. MediaTek chipset MT6762\\nMediaTek, Inc. MediaTek chipset MT6763\\nMediaTek, Inc. MediaTek chipset MT6765\\nMediaTek, Inc. MediaTek chipset MT6767\\nMediaTek, Inc. MediaTek chipset MT6768\\nMediaTek, Inc. MediaTek chipset MT6769\\nMediaTek, Inc. MediaTek chipset MT6771\\nMediaTek, Inc. MediaTek chipset MT6779\\nMediaTek, Inc. MediaTek chipset MT6781\\nMediaTek, Inc. MediaTek chipset MT6783\\nMediaTek, Inc. MediaTek chipset MT6785\\nMediaTek, Inc. MediaTek chipset MT6789\\nMediaTek, Inc. MediaTek chipset MT6813\\nMediaTek, Inc. MediaTek chipset MT6815\\nMediaTek, Inc. MediaTek chipset MT6833\\nMediaTek, Inc. MediaTek chipset MT6835\\nMediaTek, Inc. MediaTek chipset MT6853\\nMediaTek, Inc. MediaTek chipset MT6855\\nMediaTek, Inc. MediaTek chipset MT6858\\nMediaTek, Inc. MediaTek chipset MT6873\\nMediaTek, Inc. MediaTek chipset MT6875\\nMediaTek, Inc. MediaTek chipset MT6877\\nMediaTek, Inc. MediaTek chipset MT6878\\nMediaTek, Inc. MediaTek chipset MT6879\\nMediaTek, Inc. MediaTek chipset MT6880\\nMediaTek, Inc. MediaTek chipset MT6883\\nMediaTek, Inc. MediaTek chipset MT6885\\nMediaTek, Inc. MediaTek chipset MT6886\\nMediaTek, Inc. MediaTek chipset MT6889\\nMediaTek, Inc. MediaTek chipset MT6890\\nMediaTek, Inc. MediaTek chipset MT6891\\nMediaTek, Inc. MediaTek chipset MT6893\\nMediaTek, Inc. MediaTek chipset MT6895\\nMediaTek, Inc. MediaTek chipset MT6896\\nMediaTek, Inc. MediaTek chipset MT6897\\nMediaTek, Inc. MediaTek chipset MT6899\\nMediaTek, Inc. MediaTek chipset MT6980\\nMediaTek, Inc. MediaTek chipset MT6983\\nMediaTek, Inc. MediaTek chipset MT6985\\nMediaTek, Inc. MediaTek chipset MT6986D\\nMediaTek, Inc. MediaTek chipset MT6988\\nMediaTek, Inc. MediaTek chipset MT6989\\nMediaTek, Inc. MediaTek chipset MT6990\\nMediaTek, Inc. MediaTek chipset MT6991\\nMediaTek, Inc. MediaTek chipset MT6993\\nMediaTek, Inc. MediaTek chipset MT8668\\nMediaTek, Inc. MediaTek chipset MT8673\\nMediaTek, Inc. MediaTek chipset MT8675\\nMediaTek, Inc. MediaTek chipset MT8676\\nMediaTek, Inc. MediaTek chipset MT8678\\nMediaTek, Inc. MediaTek chipset MT8755\\nMediaTek, Inc. MediaTek chipset MT8771\\nMediaTek, Inc. MediaTek chipset MT8775\\nMediaTek, Inc. MediaTek chipset MT8791\\nMediaTek, Inc. MediaTek chipset MT8791T\\nMediaTek, Inc. MediaTek chipset MT8792\\nMediaTek, Inc. MediaTek chipset MT8793\\nMediaTek, Inc. MediaTek chipset MT8795T\\nMediaTek, Inc. MediaTek chipset MT8797\\nMediaTek, Inc. MediaTek chipset MT8798\\nMediaTek, Inc. MediaTek chipset MT8863\\nMediaTek, Inc. MediaTek chipset MT8873\\nMediaTek, Inc. MediaTek chipset MT8883\\nMediaTek, Inc. MediaTek chipset MT8893&#8243;,&#8221;sourceHref&#8221;:&#8221;&#8221;,&#8221;cvss&#8221;:{&#8220;score&#8221;:6.5,&#8221;severity&#8221;:&#8221;MEDIUM&#8221;,&#8221;vector&#8221;:&#8221;CVSS:3.1\/AV:A\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H&#8221;,&#8221;version&#8221;:&#8221;3.1&#8243;},&#8221;cvss2&#8243;:{},&#8221;cvss3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;,&#8221;cvssV3&#8243;:{&#8220;version&#8221;:&#8221;&#8221;,&#8221;vectorString&#8221;:&#8221;&#8221;,&#8221;baseScore&#8221;:0,&#8221;baseSeverity&#8221;:&#8221;&#8221;,&#8221;attackVector&#8221;:&#8221;&#8221;,&#8221;attackComplexity&#8221;:&#8221;&#8221;,&#8221;privilegesRequired&#8221;:&#8221;&#8221;,&#8221;userInteraction&#8221;:&#8221;&#8221;,&#8221;scope&#8221;:&#8221;&#8221;,&#8221;confidentialityImpact&#8221;:&#8221;&#8221;,&#8221;integrityImpact&#8221;:&#8221;&#8221;,&#8221;availabilityImpact&#8221;:&#8221;&#8221;}},&#8221;href&#8221;:&#8221;&#8221;,&#8221;category_name&#8221;:&#8221;CVE&#8221;,&#8221;post_link&#8221;:&#8221;&#8221;,&#8221;product&#8221;:&#8221;MediaTek chipset&#8221;,&#8221;version&#8221;:&#8221;MT2735&#8243;,&#8221;vendor&#8221;:&#8221;MediaTek, Inc.&#8221;,&#8221;ai_description&#8221;:&#8221;&#8221;,&#8221;ai_severity&#8221;:&#8221;&#8221;,&#8221;ai_vendor&#8221;:&#8221;&#8221;,&#8221;ai_product&#8221;:&#8221;&#8221;,&#8221;ai_version&#8221;:&#8221;&#8221;,&#8221;ai_score&#8221;:0}<\/p>\n","protected":false},"excerpt":{"rendered":"<p>{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[6,8,26,12,21,13,7,11,5],"class_list":["post-51211","post","type-post","status-publish","format-standard","hentry","category-category_cve","tag-cve","tag-cvss","tag-cvss-65","tag-exploit","tag-medium","tag-news","tag-security","tag-tapic","tag-vulnerability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>CVE-2026-20449_CVE-2026-20449 - zero redgem<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zero.redgem.net\/?p=51211\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CVE-2026-20449_CVE-2026-20449 - zero redgem\" \/>\n<meta property=\"og:description\" content=\"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zero.redgem.net\/?p=51211\" \/>\n<meta property=\"og:site_name\" content=\"zero redgem\" \/>\n<meta property=\"article:published_time\" content=\"2026-05-04T08:28:43+00:00\" \/>\n<meta name=\"author\" content=\"invoker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"invoker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211\"},\"author\":{\"name\":\"invoker\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\"},\"headline\":\"CVE-2026-20449_CVE-2026-20449\",\"datePublished\":\"2026-05-04T08:28:43+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211\"},\"wordCount\":514,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"keywords\":[\"CVE\",\"CVSS\",\"CVSS-6.5\",\"exploit\",\"MEDIUM\",\"news\",\"Security\",\"tapic\",\"Vulnerability\"],\"articleSection\":[\"category_cve\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=51211#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211\",\"name\":\"CVE-2026-20449_CVE-2026-20449 - zero redgem\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\"},\"datePublished\":\"2026-05-04T08:28:43+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/zero.redgem.net\\\/?p=51211\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/?p=51211#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/zero.redgem.net\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CVE-2026-20449_CVE-2026-20449\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#website\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"name\":\"zero redgem\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/zero.redgem.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#organization\",\"name\":\"zero redgem\",\"url\":\"https:\\\/\\\/zero.redgem.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"\",\"contentUrl\":\"\",\"width\":191,\"height\":188,\"caption\":\"zero redgem\"},\"image\":{\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/zero.redgem.net\\\/#\\\/schema\\\/person\\\/fbfeae8dfad117ac08a7621bee1a1dca\",\"name\":\"invoker\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g\",\"caption\":\"invoker\"},\"sameAs\":[\"https:\\\/\\\/zero.redgem.net\"],\"url\":\"https:\\\/\\\/zero.redgem.net\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CVE-2026-20449_CVE-2026-20449 - zero redgem","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zero.redgem.net\/?p=51211","og_locale":"en_US","og_type":"article","og_title":"CVE-2026-20449_CVE-2026-20449 - zero redgem","og_description":"{&#8220;lastseen&#8221;:&#8221;&#8221;,&#8221;description&#8221;:&#8221;In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE...","og_url":"https:\/\/zero.redgem.net\/?p=51211","og_site_name":"zero redgem","article_published_time":"2026-05-04T08:28:43+00:00","author":"invoker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"invoker","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/zero.redgem.net\/?p=51211#article","isPartOf":{"@id":"https:\/\/zero.redgem.net\/?p=51211"},"author":{"name":"invoker","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca"},"headline":"CVE-2026-20449_CVE-2026-20449","datePublished":"2026-05-04T08:28:43+00:00","mainEntityOfPage":{"@id":"https:\/\/zero.redgem.net\/?p=51211"},"wordCount":514,"commentCount":0,"publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"keywords":["CVE","CVSS","CVSS-6.5","exploit","MEDIUM","news","Security","tapic","Vulnerability"],"articleSection":["category_cve"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/zero.redgem.net\/?p=51211#respond"]}]},{"@type":"WebPage","@id":"https:\/\/zero.redgem.net\/?p=51211","url":"https:\/\/zero.redgem.net\/?p=51211","name":"CVE-2026-20449_CVE-2026-20449 - zero redgem","isPartOf":{"@id":"https:\/\/zero.redgem.net\/#website"},"datePublished":"2026-05-04T08:28:43+00:00","breadcrumb":{"@id":"https:\/\/zero.redgem.net\/?p=51211#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zero.redgem.net\/?p=51211"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/zero.redgem.net\/?p=51211#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zero.redgem.net\/"},{"@type":"ListItem","position":2,"name":"CVE-2026-20449_CVE-2026-20449"}]},{"@type":"WebSite","@id":"https:\/\/zero.redgem.net\/#website","url":"https:\/\/zero.redgem.net\/","name":"zero redgem","description":"","publisher":{"@id":"https:\/\/zero.redgem.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zero.redgem.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/zero.redgem.net\/#organization","name":"zero redgem","url":"https:\/\/zero.redgem.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/","url":"","contentUrl":"","width":191,"height":188,"caption":"zero redgem"},"image":{"@id":"https:\/\/zero.redgem.net\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/zero.redgem.net\/#\/schema\/person\/fbfeae8dfad117ac08a7621bee1a1dca","name":"invoker","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f17c01d7338e6932bcde121cf83569393df3374625d25afd62677cfb528f2e3e?s=96&d=mm&r=g","caption":"invoker"},"sameAs":["https:\/\/zero.redgem.net"],"url":"https:\/\/zero.redgem.net\/?author=1"}]}},"_links":{"self":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/51211","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=51211"}],"version-history":[{"count":0,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=\/wp\/v2\/posts\/51211\/revisions"}],"wp:attachment":[{"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=51211"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=51211"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zero.redgem.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=51211"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}