Remote Denial of Service Vulnerability in MediaTek Modem Products
CVE-2025-20666
Key Information:
What is CVE-2025-20666?
A vulnerability exists in MediaTek's modem products that can result in a system crash when an unhandled exception occurs. This situation arises when a user equipment (UE) connects to a malicious base station controlled by an attacker. Exploitation of this vulnerability does not require user interaction, making it particularly concerning. The issue has been documented under Issue ID MSV-2933 and requires patching to prevent potential disruptions in service.
Affected Version(s)
MT2735, MT6833, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6880, MT6883, MT6885, MT6889, MT6890, MT6891, MT6893, MT8666, MT8667, MT8673, MT8675, MT8771, MT8791, MT8791T, MT8795T, MT8797, MT8798 Modem NR15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved