« Back to list

Mediatek

Mediatek Lr12a: vulnerabilities and CVEs

Mediatek Lr12a has 17 published vulnerabilities, 4 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.

CVEs17
Last 12 months4
Critical3
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-20434High (7.5)0.23%—Mar 2, 2026
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no…
CVE-2025-20727High (8.1)0.53%—Nov 4, 2025
In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no…
CVE-2025-20726High (7.5)0.48%—Nov 4, 2025
In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no…
CVE-2025-20725High (7.5)0.51%—Nov 4, 2025
In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no…
CVE-2025-20678Medium (6.5)0.36%—Jun 2, 2025
In ims service, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional…
CVE-2025-20667High (7.5)0.43%—May 5, 2025
In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no…
CVE-2024-20154High (8.8)3.9%—Jan 6, 2025
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional…
CVE-2024-20150High (7.5)0.76%—Jan 6, 2025
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID:…
CVE-2024-20077High (7.5)0.74%—Jul 1, 2024
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.…
CVE-2024-20076High (7.5)0.74%—Jul 1, 2024
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.…
CVE-2024-20039High (8.8)0.88%—Apr 1, 2024
In modem protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for…
CVE-2023-32840Medium (6.5)0.18%—Nov 6, 2023
In modem CCCI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction may be also needed for…
CVE-2023-20819Critical (9.8)0.61%—Oct 2, 2023
In CDMA PPP protocol, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege with no additional execution privilege needed. User interaction is not…
CVE-2022-26446High (7.5)1.1%—Nov 8, 2022
In Modem 4G RRC, there is a possible system crash due to improper input validation. This could lead to remote denial of service, when concatenating improper SIB12 (CMAS message), with no additional execution privileges…
CVE-2022-21744Critical (9.8)3.4%—Jul 6, 2022
In Modem 2G RR, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding GPRS Packet Neighbour Cell Data (PNCD) improper neighbouring cell size with…
CVE-2022-20083Critical (9.8)2.8%—Jul 6, 2022
In Modem 2G/3G CC, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution when decoding combined FACILITY with no additional execution privileges needed. User…
CVE-2021-40148High (7.5)0.74%—Jan 4, 2022
In Modem EMM, there is a possible information disclosure due to a missing data encryption. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed…

Other products by Mediatek