CVE-2025-20670
5.7
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.1 / Impact: 3.6
Source: NVD
Description
In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01334347; Issue ID: MSV-2772.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions |
| Running on/with | Platform Versions |
|---|---|
Mediatek Mt2737 | All versions |
Mediatek Mt6813 | All versions |
Mediatek Mt6835 | All versions |
Mediatek Mt6835t | All versions |
Mediatek Mt6878 | All versions |
Mediatek Mt6878m | All versions |
Mediatek Mt6879 | All versions |
Mediatek Mt6886 | All versions |
Mediatek Mt6895 | All versions |
Mediatek Mt6895tt | All versions |
Mediatek Mt6896 | All versions |
Mediatek Mt6897 | All versions |
Mediatek Mt6899 | All versions |
Mediatek Mt6980 | All versions |
Mediatek Mt6980d | All versions |
Mediatek Mt6983 | All versions |
Mediatek Mt6983t | All versions |
Mediatek Mt6985 | All versions |
Mediatek Mt6985t | All versions |
Mediatek Mt6989 | All versions |
Mediatek Mt6989t | All versions |
Mediatek Mt6990 | All versions |
Mediatek Mt6991 | All versions |
Mediatek Mt8666 | All versions |
Mediatek Mt8667 | All versions |
Mediatek Mt8673 | All versions |
Mediatek Mt8675 | All versions |
Mediatek Mt8676 | All versions |
Mediatek Mt8678 | All versions |
Mediatek Mt8765 | All versions |
Mediatek Mt8766 | All versions |
Mediatek Mt8768 | All versions |
Mediatek Mt8771 | All versions |
Mediatek Mt8781 | All versions |
Mediatek Mt8786 | All versions |
Mediatek Mt8788 | All versions |
Mediatek Mt8788e | All versions |
Mediatek Mt8789 | All versions |
Mediatek Mt8791 | All versions |
Mediatek Mt8791t | All versions |
Mediatek Mt8795t | All versions |
Mediatek Mt8797 | All versions |
Mediatek Mt8798 | All versions |
References (1)
Source: security@mediatek.com
Vendor Advisory
Timeline
No history available yet.