Remote Denial of Service Vulnerability in Mediatek Modem Products
CVE-2025-20753

5.3MEDIUM

What is CVE-2025-20753?

In Modem products by Mediatek, an unhandled exception can cause system instability, allowing an attacker to induce a denial of service by taking control of a rogue base station. Notably, this vulnerability requires no user interaction and can be exploited effortlessly if a user equipment connects to the compromised base station, leading to a service disruption.

Affected Version(s)

MT2735, MT2737, MT6833, MT6833P, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT8675, MT8771, MT8791, MT8791T, MT8797 Modem NR15, NR16

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.