CVE-2026-20463
MEDIUMMediaTek Chipset - Improper Handling of Insufficient Permissions or Privileges
Title source: ruleExploitation Summary
EIP tracks 1 public exploit for CVE-2026-20463. PoCs published by HermesNA-1.
AI-analyzed exploit summary This repository contains an auto-generated stub module for CVE-2026-20463, a local privilege escalation (LPE) vulnerability in MediaTek modem firmware due to a permissions bypass. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details.
Description
In Modem, there is a possible escalation of privilege due to a permissions bypass. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: MOLY01716533; Issue ID: MSV-6309.
Exploits (1)
This repository contains an auto-generated stub module for CVE-2026-20463, a local privilege escalation (LPE) vulnerability in MediaTek modem firmware due to a permissions bypass. The code includes placeholder methods (`check` and `run`) but lacks actual exploit implementation or technical details.
References (1)
Scores
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H