
A MediaTek modem input validation issue can cause a system crash (remote DoS) when a UE connects to a rogue base station controlled by an attacker with no user interaction required.
A MediaTek modem input validation issue can cause a system crash (remote DoS) when a UE connects to a rogue base station controlled by an attacker with no user interaction required.
The provided check.sh code is used to:
To excecute -> bash ./check.sh
The flaw exists in the modem firmware's message processing routines. It fails to properly validate the boundaries of incoming data before writing it to memory buffers. This lack of validation allows a malicious base station to send data that overwrites memory it shouldn't, corrupting the modem's state and causing a crash.
Root Cause: Improper input validation leading to an out-of-bounds write (CWE-787).
Patch: MediaTek has released a fix identified as Patch ID: MOLY01689248.
Official Source: MediaTek's February 2026 Product Security Bulletin details this and related vulnerabilities.
The vulnerability impacts a broad range of MediaTek chipsets, including but not limited to:
Chipset Series Example Models: