MEDIUM 5.3

CVE-2026-20459: Modem Denial of Service via Rogue Base Station Attack

A flaw in cellular modem firmware allows an attacker operating a rogue base station to crash a device's modem, temporarily knocking it offline. The vulnerability requires no special privileges and occurs automatically when a user connects to the attacker's malicious network. It does not lead to data theft or system compromise, but causes service disruption.

Source data · NVD / CISA · public domain

CVSS
3.1 · 5.3 MEDIUM · CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weaknesses (CWE)
CWE-288
Affected products
0 configuration(s)
Published / Modified
2026-07-01 / 2026-07-01

NVD description (verbatim)

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01816800; Issue ID: MSV-6842.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-20459 is an improper input validation flaw in modem firmware that triggers a denial-of-service condition. When a UE (User Equipment) connects to an attacker-controlled base station, a crafted signal or protocol message causes the modem to crash due to insufficient bounds checking or input sanitization. The attack vector is adjacent (AV:A), reflecting the requirement to operate or control network infrastructure, though access is not difficult. The attack complexity is high (AC:H), suggesting specific conditions must align. No authentication, user action, or elevated privileges are needed once the UE associates with the rogue base station. CVSS 3.1 score of 5.3 reflects a medium-severity availability impact with no confidentiality or integrity loss.

Business impact

Organizations operating or supporting mobile devices are at risk of service disruption if employees or customers connect to compromised cellular networks. While the modem crash is recoverable via restart, it can disrupt communications, productivity, and real-time operations. The risk is moderate because the attack requires the attacker to control radio infrastructure—a higher barrier than direct internet access—and does not lead to data exfiltration or persistent compromise.

Affected systems

The vulnerability resides in modem firmware and affects devices that run the affected modem software. The advisory does not specify individual device models, OEMs, or OS platforms; you must cross-reference the patch details (MOLY01816800, MSV-6842) with your vendor's security notices to determine which phones, tablets, or embedded systems are impacted. Check with your device manufacturer or cellular chipset supplier for detailed product scope.

Exploitability

Exploitation requires an attacker to operate a rogue base station—a high-cost, high-complexity setup. However, once deployed in a target area, the attack is reliable and requires no user interaction or credentials. The victim merely needs to be in range and allow the device to connect to the network. This makes the vulnerability exploitable in targeted scenarios (e.g., near sensitive facilities or high-value targets) but unlikely to be mass-exploited unless an attacker has significant resources and motivation.

Remediation

Apply the available patch (Patch ID: MOLY01816800) to your modem firmware. Coordinate with your device OEM or carrier to obtain and deploy the update. For devices unable to receive patches, consider network-level mitigations such as Rogue Base Station Detection (RBSD) or monitoring for sudden modem resets in your mobile fleet. Ensure your organization's incident response plan includes procedures for modem crashes attributed to network anomalies.

Patch guidance

Identify your modem chipset and device model, then consult your manufacturer's security advisory for Patch ID MOLY01816800. Patch availability and deployment timelines vary by OEM and carrier; some devices may receive updates via over-the-air (OTA) mechanisms, while others may require manual intervention or carrier coordination. Prioritize patching devices in high-risk roles (executives, field operatives) or those frequently in untrusted network environments. Verify the patch application by confirming the Issue ID MSV-6842 is resolved in your firmware version, per your vendor's documentation.

Detection guidance

Monitor for unexplained modem resets or dropped cellular connections, especially if they occur in clusters or specific geographic areas. Correlate modem restart logs with network signal anomalies or reports of rogue base station activity. If your organization uses Mobile Threat Defense (MTD) solutions, enable algorithms to detect suspicious base station behavior. Track firmware versions across your fleet to ensure patched builds are deployed; device management tools can facilitate this inventory.

Why prioritize this

This vulnerability merits medium priority attention. Although the CVSS score of 5.3 is moderate, the practical barrier to exploitation—requiring attacker control of cellular infrastructure—reduces urgency compared to remotely exploitable flaws. However, the lack of user interaction and the availability impact make it a candidate for rapid patching in high-risk environments such as government, finance, or healthcare where communications reliability is critical.

Risk score, explained

The CVSS 3.1 score of 5.3 (Medium) reflects the combination of high availability impact (A:H) against a backdrop of limited attack surface (AV:A, AC:H) and no confidentiality or integrity exposure (C:N, I:N). The adjacent attack vector acknowledges that radio-based attacks are generally harder to execute than internet-based ones, yet the absence of user interaction (UI:N) and authentication (PR:N) ensures the flaw remains a credible threat in targeted scenarios.

Frequently asked questions

Can this vulnerability steal or corrupt my data?

No. CVE-2026-20459 causes only a denial of service—the modem crashes and must be restarted. There is no confidentiality or integrity impact, so your data remains safe. The attacker cannot exfiltrate information or alter files on your device.

Do I need a special network to be vulnerable?

Yes and no. You are only vulnerable if you connect to a rogue base station controlled by the attacker. You cannot be exploited by legitimate networks. However, your device may automatically connect to networks it has seen before, so an attacker could set up a trap near high-value targets or in areas where your device is known to operate.

What should I do if my modem keeps crashing?

First, update your modem firmware to patch MOLY01816800 if available for your device. If crashes persist, contact your OEM or carrier support. If you suspect a rogue base station, report it to your carrier or local authorities. In the interim, you can try disabling automatic network selection and manually connecting only to trusted networks.

Is this in the Known Exploited Vulnerabilities catalog?

No, CVE-2026-20459 is not currently listed in CISA's KEV catalog, meaning there are no confirmed public exploits or active mass exploitation campaigns at this time. However, this does not preclude targeted use by sophisticated actors with the capability to operate base stations.

This analysis is based on the CVE record and available vendor information as of the publication date. Patch availability, compatibility, and timelines are the responsibility of the affected device manufacturer and carrier. Organizations must verify the applicability of Patch ID MOLY01816800 and Issue ID MSV-6842 to their specific devices and firmware versions before deployment. This document does not constitute professional security advice; consult your internal security team and vendor advisories for your environment. No exploit code or weaponizable proof-of-concept is provided herein. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).