High severity8.8NVD Advisory· Published Jan 6, 2025· Updated Jun 17, 2026
CVE-2024-20154
CVE-2024-20154
Description
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:mediatek:nr16.r1.mp1mp2.mp:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:nr16.r1.mp:-:*:*:*:*:*:*:*
- cpe:2.3:o:mediatek:nr16.r2.mp:-:*:*:*:*:*:*:*
- MediaTek, Inc./MT2735, MT6767, MT6768, MT6769, MT6769K, MT6769S, MT6769T, MT6769Z, MT6779, MT6781, MT6783, MT6785, MT6785T, MT6785U, MT6789, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6880, MT6880T, MT6880U, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT8666, MT8673, MT8675, MT8765, MT8766, MT8768, MT8771, MT8781, MT8786, MT8788, MT8788E, MT8789, MT8791T, MT8795T, MT8797, MT8798v5Range: Modem LR12A, LR13, NR15, NR16.R1.MP, NR16.R1.MP1MP2.MP, NR16.R2.MP
Patches
Vulnerability mechanics
References
1- corp.mediatek.com/product-security-bulletin/January-2025nvdVendor Advisory
News mentions
0No linked articles in our index yet.