Discovered CVEs
Jan 4, 2026
ยท
7 min read
This page lists CVEs (Common Vulnerabilities and Exposures) discovered and responsibly disclosed by my group (SysSec Lab) and collaborators, across cellular/baseband, mobile telephony, and networked devices. Entries are listed in reverse chronological order (most recent first).
- CVE-2026-56975 โ Reserved
- CVE-2026-56967 โ Reserved
- CVE-2026-28967 โ An attacker in a privileged network position can cause telephony denial of service โ Vendor: Apple โ CVSS: 4.9 โ Reported by: Hazem Issa and Yongdae Kim
- CVE-2026-28875 โ A remotely triggered baseband buffer overflow can cause denial of service โ Vendor: Apple โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, Hazem Issa, and Yongdae Kim
- CVE-2026-28874 โ A remote attacker can cause unexpected application termination through malformed baseband input โ Vendor: Apple โ CVSS: 7.5 โ Reported by: Hazem Issa, Tuan Dinh Hoang, and Yongdae Kim
- CVE-2026-28858 โ A remotely triggered telephony buffer overflow can terminate the system or corrupt kernel memory โ Vendor: Apple โ CVSS: 9.8 โ Reported by: Hazem Issa and Yongdae Kim
- CVE-2026-20499 โ Reserved
- CVE-2026-20449 โ A heap buffer overflow while processing malformed 5G MAC PDUs enables remote denial of service through a rogue base station โ Vendor: MediaTek โ CVSS: 6.5 โ Reported by: Tuan Dinh Hoang, Hazem Issa, and Yongdae Kim
- CVE-2026-0159 โ Improper handling of Rejected NSSAI information in a 5G Registration Accept message โ Vendor: Google โ CVSS: Not publicly available โ Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
- CVE-2026-0110 โ Memory corruption in 5G NR modem processing can enable remote privilege escalation โ Vendor: Google โ CVSS: 9.8 โ Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
- CVE-2025-47371 โ Processing a malformed LTE RLC transport block can cause a transient modem denial of service โ Vendor: Qualcomm โ CVSS: 6.5 โ Reported by: Tuan Dinh Hoang
- CVE-2025-36917 โ An incorrect bounds check in the PDCP security path permits remote denial of service โ Vendor: Google โ CVSS: 6.5 โ Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
- CVE-2025-36912 โ A logic error in cellular modem message processing permits remote denial of service โ Vendor: Google โ CVSS: 6.5 โ Reported by: Beomseok Oh and Yongdae Kim
- CVE-2025-26782 โ Incorrect handling of RLC acknowledged-mode PDUs leads to denial of service โ Vendor: Samsung โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
- CVE-2025-26781 โ Incorrect handling of RLC acknowledged-mode PDUs leads to denial of service โ Vendor: Samsung โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
- CVE-2025-26780 โ A missing length check in PDCP packet processing leads to denial of service โ Vendor: Samsung โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, Yongdae Kim, Insu Yun, and CheolJun Park
- CVE-2025-21477 โ Incorrect processing of a CCCH subheader length can cause a transient modem denial of service โ Vendor: Qualcomm โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
- CVE-2025-21452 โ An invalid LTE random-access response PDU length can cause a transient modem denial of service โ Vendor: Qualcomm โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
- CVE-2025-20755 โ Improper validation of an EAP message can remotely crash the modem through a rogue base station โ Vendor: MediaTek โ CVSS: 5.3 โ Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
- CVE-2025-20708 โ An out-of-bounds write in 5G PDCP processing can enable remote privilege escalation through a rogue base station โ Vendor: MediaTek โ CVSS: 8.8 โ Reported by: Tuan Dinh Hoang, Taekkyung Oh, Yongdae Kim, CheolJun Park, and Insu Yun
- CVE-2025-20659 โ Improper validation of malformed PDCP packets allows a rogue base station to cause remote denial of service โ Vendor: MediaTek โ CVSS: 6.5 โ Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
- CVE-2024-48883 โ Incorrect handling of a malformed uplink scheduling message leaks UE information โ Vendor: Samsung โ CVSS: 4.3 โ Reported by: Taekkyung Oh, Beomseok Oh, Hansung Bae, Taisic Yun, and Yongdae Kim
- CVE-2024-27870 โ Incorrect handling of a CCCH length field can remotely crash the baseband; the issue overlaps CVE-2025-21477 โ Vendor: Apple โ CVSS: Not publicly available โ Reported by: Tuan Dinh Hoang, Taekkyung Oh, CheolJun Park, Insu Yun, and Yongdae Kim
- CVE-2024-23385 โ An invalid MAC random-access response PDU length can reset the modem and cause transient denial of service โ Vendor: Qualcomm โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
- CVE-2024-20077 โ Incorrect processing of malformed MAC control elements can remotely crash the modem โ Vendor: MediaTek โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
- CVE-2024-20076 โ Incorrect error handling of malformed MAC packets can remotely crash the modem โ Vendor: MediaTek โ CVSS: 7.5 โ Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
- CVE-2024-20039 โ An out-of-bounds write in modem protocol processing can enable remote code execution โ Vendor: MediaTek โ CVSS: 8.8 โ Reported by: CheolJun Park and Marc Egli
- CVE-2023-37366 โ An unreachable-exit loop can prevent termination of a required baseband service โ Vendor: Samsung โ CVSS: 5.9 โ Reported by: Individual credit not publicly listed
- CVE-2023-32890 โ Improper input validation in the mobility-management protocol can remotely crash the modem โ Vendor: MediaTek โ CVSS: 7.5 โ Reported by: CheolJun Park and Marc Egli
- CVE-2022-40536 โ Improper authentication of a plain over-the-air request can cause a transient denial of service โ Vendor: Qualcomm โ CVSS: 7.5 โ Reported by: CheolJun Park, KAIST SysSec Lab
- CVE-2022-40521 โ Improper authorization handling in modem procedures can cause a transient denial of service โ Vendor: Qualcomm โ CVSS: 7.5 โ Reported by: CheolJun Park, KAIST SysSec Lab
- CVE-2022-23425 โ Improper input validation allows a fake base station to send arbitrary LTE NAS signaling messages โ Vendor: Samsung โ CVSS: 9.8 (NVD; vendor score 8.6) โ Reported by: Eunsoo Kim, Min Woo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, and Insu Yun
- CVE-2021-30826 โ The baseband can fail to enable integrity and ciphering protection in certain situations โ Vendor: Apple โ CVSS: 7.5 โ Reported by: CheolJun Park, Sangwook Bae, and BeomSeok Oh
- CVE-2021-25516 โ Improper handling of exceptional baseband conditions enables location tracking โ Vendor: Samsung โ CVSS: 6.4 โ Reported by: CheolJun Park, Sangwook Bae, and BeomSeok Oh
- CVE-2019-20783 โ LTE authentication and key agreement can be bypassed on affected mobile devices โ Vendor: LG Electronics โ CVSS: 6.4 โ Reported by: LTEFuzz research team
- CVE-2019-20084 โ Reserved โ D-Link
- CVE-2019-20082 โ Buffer overflow triggered by overly long DNS configuration values โ Vendor: ASUS โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2019-11400 โ Stack-based buffer overflow through a crafted ccp_act request parameter โ Vendor: TRENDnet โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2019-11399 โ OS command injection through the LAN host-name configuration parameter โ Vendor: TRENDnet โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2019-6258 โ Buffer overflow triggered by an overly long MacAddress value in SetClientInfo โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2019-5307 โ LTE message replay may alter a temporary subscriber identifier or expose the permanent subscriber identity โ Vendor: Huawei โ CVSS: 4.2 โ Reported by: Yongdae Kim, Hongil Kim, Jiho Lee, and Eunkyu Lee
- CVE-2019-2289 โ Missing integrity verification allows arbitrary LTE NAS messages to be accepted, enabling authentication bypass โ Vendor: Qualcomm โ CVSS: 9.8 โ Reported by: KAIST SysSec Lab
- CVE-2018-20114 โ Unauthenticated remote command execution through a crafted service parameter in soap.cgi โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2018-19990 โ OS command injection through the WPSPIN field in SetWiFiVerifyAlpha โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2018-19989 โ OS command injection through the uplink field in SetQoSSettings โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2018-19988 โ OS command injection through the AudioMute or AudioEnable field in SetClientInfoDemo โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2018-19987 โ OS command injection through the IsAccessPoint field in SetAccessPointMode โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2018-19986 โ OS command injection through the RemotePort field in SetRouterSettings โ Vendor: D-Link โ CVSS: 9.8 โ Reported by: Mingeun Kim, KAIST SysSec Lab
- CVE-2015-6614 โ Crafted applications can bypass telephony interface restrictions, enabling unauthorized data transfers or denial of service โ Vendor: Google/Android โ CVSS: 5.8 (v2) โ Reported by: Hongil Kim, Dongkwan Kim, Minhee Kwon, Hyungseok Han, Yeongjin Jang, Dongsu Han, Taesoo Kim, and Yongdae Kim