Discovered CVEs

Jan 4, 2026 ยท 7 min read

This page lists CVEs (Common Vulnerabilities and Exposures) discovered and responsibly disclosed by my group (SysSec Lab) and collaborators, across cellular/baseband, mobile telephony, and networked devices. Entries are listed in reverse chronological order (most recent first).

  1. CVE-2026-56975 โ€” Reserved
  2. CVE-2026-56967 โ€” Reserved
  3. CVE-2026-28967 โ€” An attacker in a privileged network position can cause telephony denial of service โ€” Vendor: Apple โ€” CVSS: 4.9 โ€” Reported by: Hazem Issa and Yongdae Kim
  4. CVE-2026-28875 โ€” A remotely triggered baseband buffer overflow can cause denial of service โ€” Vendor: Apple โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, Hazem Issa, and Yongdae Kim
  5. CVE-2026-28874 โ€” A remote attacker can cause unexpected application termination through malformed baseband input โ€” Vendor: Apple โ€” CVSS: 7.5 โ€” Reported by: Hazem Issa, Tuan Dinh Hoang, and Yongdae Kim
  6. CVE-2026-28858 โ€” A remotely triggered telephony buffer overflow can terminate the system or corrupt kernel memory โ€” Vendor: Apple โ€” CVSS: 9.8 โ€” Reported by: Hazem Issa and Yongdae Kim
  7. CVE-2026-20499 โ€” Reserved
  8. CVE-2026-20449 โ€” A heap buffer overflow while processing malformed 5G MAC PDUs enables remote denial of service through a rogue base station โ€” Vendor: MediaTek โ€” CVSS: 6.5 โ€” Reported by: Tuan Dinh Hoang, Hazem Issa, and Yongdae Kim
  9. CVE-2026-0159 โ€” Improper handling of Rejected NSSAI information in a 5G Registration Accept message โ€” Vendor: Google โ€” CVSS: Not publicly available โ€” Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
  10. CVE-2026-0110 โ€” Memory corruption in 5G NR modem processing can enable remote privilege escalation โ€” Vendor: Google โ€” CVSS: 9.8 โ€” Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
  11. CVE-2025-47371 โ€” Processing a malformed LTE RLC transport block can cause a transient modem denial of service โ€” Vendor: Qualcomm โ€” CVSS: 6.5 โ€” Reported by: Tuan Dinh Hoang
  12. CVE-2025-36917 โ€” An incorrect bounds check in the PDCP security path permits remote denial of service โ€” Vendor: Google โ€” CVSS: 6.5 โ€” Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
  13. CVE-2025-36912 โ€” A logic error in cellular modem message processing permits remote denial of service โ€” Vendor: Google โ€” CVSS: 6.5 โ€” Reported by: Beomseok Oh and Yongdae Kim
  14. CVE-2025-26782 โ€” Incorrect handling of RLC acknowledged-mode PDUs leads to denial of service โ€” Vendor: Samsung โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
  15. CVE-2025-26781 โ€” Incorrect handling of RLC acknowledged-mode PDUs leads to denial of service โ€” Vendor: Samsung โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
  16. CVE-2025-26780 โ€” A missing length check in PDCP packet processing leads to denial of service โ€” Vendor: Samsung โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, Yongdae Kim, Insu Yun, and CheolJun Park
  17. CVE-2025-21477 โ€” Incorrect processing of a CCCH subheader length can cause a transient modem denial of service โ€” Vendor: Qualcomm โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
  18. CVE-2025-21452 โ€” An invalid LTE random-access response PDU length can cause a transient modem denial of service โ€” Vendor: Qualcomm โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
  19. CVE-2025-20755 โ€” Improper validation of an EAP message can remotely crash the modem through a rogue base station โ€” Vendor: MediaTek โ€” CVSS: 5.3 โ€” Reported by: Martin Crettol, Beomseok Oh, and Yongdae Kim
  20. CVE-2025-20708 โ€” An out-of-bounds write in 5G PDCP processing can enable remote privilege escalation through a rogue base station โ€” Vendor: MediaTek โ€” CVSS: 8.8 โ€” Reported by: Tuan Dinh Hoang, Taekkyung Oh, Yongdae Kim, CheolJun Park, and Insu Yun
  21. CVE-2025-20659 โ€” Improper validation of malformed PDCP packets allows a rogue base station to cause remote denial of service โ€” Vendor: MediaTek โ€” CVSS: 6.5 โ€” Reported by: Tuan Dinh Hoang, Yongdae Kim, and CheolJun Park
  22. CVE-2024-48883 โ€” Incorrect handling of a malformed uplink scheduling message leaks UE information โ€” Vendor: Samsung โ€” CVSS: 4.3 โ€” Reported by: Taekkyung Oh, Beomseok Oh, Hansung Bae, Taisic Yun, and Yongdae Kim
  23. CVE-2024-27870 โ€” Incorrect handling of a CCCH length field can remotely crash the baseband; the issue overlaps CVE-2025-21477 โ€” Vendor: Apple โ€” CVSS: Not publicly available โ€” Reported by: Tuan Dinh Hoang, Taekkyung Oh, CheolJun Park, Insu Yun, and Yongdae Kim
  24. CVE-2024-23385 โ€” An invalid MAC random-access response PDU length can reset the modem and cause transient denial of service โ€” Vendor: Qualcomm โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
  25. CVE-2024-20077 โ€” Incorrect processing of malformed MAC control elements can remotely crash the modem โ€” Vendor: MediaTek โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
  26. CVE-2024-20076 โ€” Incorrect error handling of malformed MAC packets can remotely crash the modem โ€” Vendor: MediaTek โ€” CVSS: 7.5 โ€” Reported by: Tuan Dinh Hoang, CheolJun Park, Mincheol Son, Taekkyung Oh, and Yongdae Kim
  27. CVE-2024-20039 โ€” An out-of-bounds write in modem protocol processing can enable remote code execution โ€” Vendor: MediaTek โ€” CVSS: 8.8 โ€” Reported by: CheolJun Park and Marc Egli
  28. CVE-2023-37366 โ€” An unreachable-exit loop can prevent termination of a required baseband service โ€” Vendor: Samsung โ€” CVSS: 5.9 โ€” Reported by: Individual credit not publicly listed
  29. CVE-2023-32890 โ€” Improper input validation in the mobility-management protocol can remotely crash the modem โ€” Vendor: MediaTek โ€” CVSS: 7.5 โ€” Reported by: CheolJun Park and Marc Egli
  30. CVE-2022-40536 โ€” Improper authentication of a plain over-the-air request can cause a transient denial of service โ€” Vendor: Qualcomm โ€” CVSS: 7.5 โ€” Reported by: CheolJun Park, KAIST SysSec Lab
  31. CVE-2022-40521 โ€” Improper authorization handling in modem procedures can cause a transient denial of service โ€” Vendor: Qualcomm โ€” CVSS: 7.5 โ€” Reported by: CheolJun Park, KAIST SysSec Lab
  32. CVE-2022-23425 โ€” Improper input validation allows a fake base station to send arbitrary LTE NAS signaling messages โ€” Vendor: Samsung โ€” CVSS: 9.8 (NVD; vendor score 8.6) โ€” Reported by: Eunsoo Kim, Min Woo Baek, CheolJun Park, Dongkwan Kim, Yongdae Kim, and Insu Yun
  33. CVE-2021-30826 โ€” The baseband can fail to enable integrity and ciphering protection in certain situations โ€” Vendor: Apple โ€” CVSS: 7.5 โ€” Reported by: CheolJun Park, Sangwook Bae, and BeomSeok Oh
  34. CVE-2021-25516 โ€” Improper handling of exceptional baseband conditions enables location tracking โ€” Vendor: Samsung โ€” CVSS: 6.4 โ€” Reported by: CheolJun Park, Sangwook Bae, and BeomSeok Oh
  35. CVE-2019-20783 โ€” LTE authentication and key agreement can be bypassed on affected mobile devices โ€” Vendor: LG Electronics โ€” CVSS: 6.4 โ€” Reported by: LTEFuzz research team
  36. CVE-2019-20084 โ€” Reserved โ€” D-Link
  37. CVE-2019-20082 โ€” Buffer overflow triggered by overly long DNS configuration values โ€” Vendor: ASUS โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  38. CVE-2019-11400 โ€” Stack-based buffer overflow through a crafted ccp_act request parameter โ€” Vendor: TRENDnet โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  39. CVE-2019-11399 โ€” OS command injection through the LAN host-name configuration parameter โ€” Vendor: TRENDnet โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  40. CVE-2019-6258 โ€” Buffer overflow triggered by an overly long MacAddress value in SetClientInfo โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  41. CVE-2019-5307 โ€” LTE message replay may alter a temporary subscriber identifier or expose the permanent subscriber identity โ€” Vendor: Huawei โ€” CVSS: 4.2 โ€” Reported by: Yongdae Kim, Hongil Kim, Jiho Lee, and Eunkyu Lee
  42. CVE-2019-2289 โ€” Missing integrity verification allows arbitrary LTE NAS messages to be accepted, enabling authentication bypass โ€” Vendor: Qualcomm โ€” CVSS: 9.8 โ€” Reported by: KAIST SysSec Lab
  43. CVE-2018-20114 โ€” Unauthenticated remote command execution through a crafted service parameter in soap.cgi โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  44. CVE-2018-19990 โ€” OS command injection through the WPSPIN field in SetWiFiVerifyAlpha โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  45. CVE-2018-19989 โ€” OS command injection through the uplink field in SetQoSSettings โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  46. CVE-2018-19988 โ€” OS command injection through the AudioMute or AudioEnable field in SetClientInfoDemo โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  47. CVE-2018-19987 โ€” OS command injection through the IsAccessPoint field in SetAccessPointMode โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  48. CVE-2018-19986 โ€” OS command injection through the RemotePort field in SetRouterSettings โ€” Vendor: D-Link โ€” CVSS: 9.8 โ€” Reported by: Mingeun Kim, KAIST SysSec Lab
  49. CVE-2015-6614 โ€” Crafted applications can bypass telephony interface restrictions, enabling unauthorized data transfers or denial of service โ€” Vendor: Google/Android โ€” CVSS: 5.8 (v2) โ€” Reported by: Hongil Kim, Dongkwan Kim, Minhee Kwon, Hyungseok Han, Yeongjin Jang, Dongsu Han, Taesoo Kim, and Yongdae Kim