HIGH 7.5

CVE-2026-20458: Modem Memory Corruption Remote Privilege Escalation

A memory corruption flaw in cellular modems could allow an attacker to gain elevated system privileges if a device connects to a malicious base station the attacker controls. The vulnerability requires the attacker to operate or compromise a base station, but once a user's phone or modem connects to it, no further interaction or special privileges are needed to exploit the flaw. This is a serious risk for any organization with field personnel or devices that roam across cellular networks.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
CWE-787
Affected products
0 configuration(s)
Published / Modified
2026-07-01 / 2026-07-02

NVD description (verbatim)

In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01402160; Issue ID: MSV-7298.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-20458 is a missing bounds check vulnerability (CWE-787: Out-of-bounds Write) in modem firmware that permits remote memory corruption. An attacker controlling a rogue base station can transmit crafted wireless signals that trigger an out-of-bounds write in the modem's memory space, corrupting critical data structures. Because the modem runs with elevated privileges and maintains access to system resources before user authentication, successful exploitation results in privilege escalation from the cellular subsystem to system or kernel level, depending on the architecture and privilege separation implementation.

Business impact

Compromised modems become beachheads for lateral movement into corporate networks. An attacker exploiting this vulnerability can establish persistent control over a device's cellular subsystem, intercept or modify communications, exfiltrate sensitive data, and pivot to the main processor and application processor. For enterprises managing fleets of IoT devices, automotive telemetry systems, or field workforces relying on cellular connectivity, this vulnerability threatens both confidentiality and integrity of transmitted data and stored secrets. Remote exploitation via rogue base station infrastructure means the attack surface extends beyond traditional network perimeters.

Affected systems

The vulnerability affects modem components across devices that support cellular connectivity. Although specific vendor and product information is not enumerated in available data, cellular modems are present in smartphones, tablets, laptops with LTE/5G modules, automotive connected systems, and industrial IoT devices. Organizations should audit their device inventory for any cellular-connected hardware and cross-reference with vendor security bulletins to identify affected models and firmware versions. Manufacturers typically release firmware patches through device system updates or dedicated modem update mechanisms.

Exploitability

Exploitation requires an attacker to establish or control a cellular base station (femtocell, picocell, or network infrastructure) and position it within range of target devices. This is a moderate operational hurdle for a sophisticated threat actor but not a high-complexity attack. Once proximity is achieved, the attack is reliable and requires no user interaction—devices connecting to the rogue base station are vulnerable automatically. The CVSS vector (AV:A for Adjacent Network) reflects that the attacker must be on the same cellular network segment. The High attack complexity (AC:H) accounts for the need to control base station infrastructure, but this does not imply the vulnerability is difficult to trigger once the setup is in place.

Remediation

Apply the modem firmware patch identified as MOLY01402160 (Issue ID: MSV-7298) as soon as it is available and tested in your environment. For consumer devices, patches typically arrive as over-the-air (OTA) system updates; check your device settings for pending updates. For enterprise-managed devices, coordinate with mobile device management (MDM) solutions to deploy firmware updates across your fleet. Organizations in sensitive locations or with high-value targets should prioritize patching. Until patches are deployed, consider restricting roaming to trusted carrier networks and disabling non-essential cellular connectivity in restricted environments if operationally feasible.

Patch guidance

Verify patch availability through your device manufacturer's security advisory portal and cross-reference the patch ID MOLY01402160 with official release notes. For devices you manage directly, obtain the patch through manufacturer channels and test in a representative environment before broad deployment. If your organization uses MDM tools, configure automatic or managed deployment of modem firmware updates. Document patch deployment status to demonstrate compliance with vulnerability remediation SLAs. Note that modem firmware patches may require device restart or may be bundled with broader OS updates; coordinate with change management and end-user communication teams.

Detection guidance

Detection of exploitation is challenging because the attack occurs at the modem layer, often below visibility of standard endpoint detection tools. Implement network-level monitoring for unusual cellular behavior: abnormal data volumes, unexpected roaming events, or connections to base stations with unusual characteristics. Enable modem logging on devices where available and review logs for memory faults, signal processing errors, or unexplained resets. Monitor for post-exploitation indicators such as unusual process launches at the kernel level, privilege escalation attempts, or unexpected system service modifications. Coordinate with your cellular carrier to report suspected rogue base station activity and request IMSI catcher detection support if available.

Why prioritize this

This vulnerability scores CVSS 7.5 (High severity) with impact across confidentiality, integrity, and availability. Remote privilege escalation without user interaction is a critical threat pattern. Although exploitation requires base station control, the barrier is not prohibitively high for organized threat actors, and the impact—full system compromise—justifies urgent attention. Organizations with mobile workforces, IoT deployments, or geographically dispersed field teams should prioritize this as part of their critical patching cycle. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities list, but this may reflect recent disclosure; do not defer patching based on KEV status alone.

Risk score, explained

The CVSS 7.5 (High) rating reflects the combination of high impact (confidentiality, integrity, and availability all marked as High), no special privileges required, no user interaction, and remote network-adjacent attack vector. The attack complexity is rated High because the attacker must set up or control a cellular base station, a non-trivial operational requirement. However, the scope is Unchanged, meaning the privileges gained remain within the modem's security domain (albeit elevated), and the overall risk is driven by the realistic ability of determined threat actors to stage such an attack and the severity of the resulting compromise.

Frequently asked questions

Can my phone be compromised just by being near a rogue base station?

Yes. If your phone or cellular-equipped device connects to a rogue base station operated by an attacker, the vulnerability can be triggered automatically without any action on your part. The modem firmware flaw allows the attacker to corrupt memory and gain privilege, and this can happen in the background without user awareness.

What should I do if I work in an area where I cannot immediately patch my device?

Patch as soon as feasible, but in the interim, consider disabling cellular connectivity if your work environment allows it, or restricting roaming to known, trusted carrier networks. Avoid high-risk geographic areas if possible. Ensure your device's security software is up to date and monitor for signs of unusual behavior such as unexpected reboots, rapid battery drain, or unusual data usage.

Is this vulnerability actively exploited in the wild?

The vulnerability was disclosed on July 1, 2026, and is not yet listed on CISA's Known Exploited Vulnerabilities (KEV) catalog. However, recent disclosure does not guarantee lack of exploitation. Sophisticated threat actors may exploit zero-days or newly disclosed vulnerabilities before patches are widely deployed. Patch urgently and monitor for indicators of compromise.

Who is responsible for patching—my phone manufacturer or my carrier?

Both play roles. The modem firmware patch (MOLY01402160) comes from the modem chipset manufacturer, but it is typically integrated into the device OS update distributed by your phone manufacturer and/or carrier. Contact your device manufacturer's support or check your device settings for available updates. If you use an MDM service, your IT team may orchestrate updates across your device fleet.

This analysis is provided for informational purposes to assist security professionals in understanding and remediating CVE-2026-20458. The information herein reflects publicly disclosed vulnerability details and general security best practices. Specific patch availability, affected product lists, and deployment timelines must be verified with official vendor advisories and your organization's vendor management processes. SEC.co makes no warranty regarding the completeness or accuracy of third-party vendor information and recommends independent verification before making business or compliance decisions. Test patches in a representative environment before production deployment. This publication does not constitute legal or compliance advice. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).