In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00720348; Issue ID: MSV-2392.
Cite this page
CVE-2024-20154. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-20154
Use CWE-121, Mediatek vendor hub and Lr12a product page to widen CVE-2024-20154 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-20039, CVE-2025-20727 and CVE-2026-20434 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 6th, 2026.