Remote Denial of Service Vulnerability in MediaTek Modem
CVE-2025-20761

7.5HIGH

What is CVE-2025-20761?

A flaw in MediaTek's modem arises from improper error handling during specific conditions. This vulnerability allows a potential attacker to induce a system crash by establishing a connection with a rogue base station. Notably, the exploitation requires no additional execution privileges or user interaction, thus heightening the risk. Users connected to manipulated base stations can experience a disruption in service, which could severely impact operations.

Affected Version(s)

MT2735, MT2737, MT6833, MT6833P, MT6835, MT6835T, MT6853, MT6853T, MT6855, MT6855T, MT6873, MT6875, MT6875T, MT6877, MT6877T, MT6877TT, MT6879, MT6880, MT6883, MT6885, MT6886, MT6889, MT6890, MT6891, MT6893, MT6895, MT6895TT, MT6896, MT6897, MT6980, MT6980D, MT6983, MT6983T, MT6985, MT6985T, MT6989, MT6989T, MT6990, MT8673, MT8675, MT8676, MT8678, MT8755, MT8771, MT8791, MT8791T, MT8792, MT8793, MT8795T, MT8797, MT8798, MT8863, MT8873, MT8883, MT8893 Modem NR15, NR16, NR17

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-20761 : Remote Denial of Service Vulnerability in MediaTek Modem