CVE-2021-32486
📋 TL;DR
This vulnerability is a heap buffer overflow in the 2G Radio Resource Management (RRM) component of MediaTek modems. It allows remote attackers to cause a system crash (denial of service) without requiring user interaction or special privileges. Affected systems include devices using vulnerable MediaTek modem chipsets.
💻 Affected Systems
- MediaTek modem chipsets with 2G RRM functionality
📦 What is this software?
Modem by Mediatek
Modem by Mediatek
⚠️ Risk & Real-World Impact
Worst Case
Complete system crash requiring hardware reset, potentially disrupting all cellular connectivity functions on the device.
Likely Case
Temporary denial of service affecting cellular connectivity until system recovery or reboot.
If Mitigated
No impact if patched; unpatched systems remain vulnerable to remote DoS attacks.
🎯 Exploit Status
Requires sending specially crafted 2G network packets to vulnerable modem.
🛠️ Fix & Mitigation
✅ Official Fix
Patch Version: Patch ID: MOLY00500621
Vendor Advisory: https://corp.mediatek.com/product-security-bulletin/September-2021
Restart Required: Yes
Instructions:
1. Contact device manufacturer for firmware updates. 2. Apply MediaTek modem firmware patch MOLY00500621. 3. Reboot device after patch installation.
🔧 Temporary Workarounds
Disable 2G Network Mode
androidForce device to use 3G/4G/5G only to avoid 2G RRM component exposure
Settings > Network & Internet > Mobile network > Preferred network type > Select 3G/4G/5G only
🧯 If You Can't Patch
- Isolate vulnerable devices from untrusted cellular networks
- Implement network monitoring for abnormal 2G traffic patterns
🔍 How to Verify
Check if Vulnerable:
Check modem firmware version against MediaTek security bulletin; devices with patch MOLY00500621 applied are fixed.
Check Version:
Device-specific; typically requires manufacturer diagnostic tools or system logs.
Verify Fix Applied:
Verify modem firmware includes patch MOLY00500621 via device diagnostic tools or manufacturer verification.
📡 Detection & Monitoring
Log Indicators:
- Modem crash logs
- Unexpected modem resets
- 2G RRM error messages
Network Indicators:
- Abnormal 2G network traffic patterns
- Unexpected 2G protocol messages
SIEM Query:
Search for modem crash events or 2G RRM error codes in device/system logs