← Back

CVE-2025-20704

nvd nist
Published: Sep 1, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.0
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.1 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.

Affected (2)

Products: Mediatek: Nr17, Nr17r
2 products
Nr17
Nr17r
Configuration A
2 vulnerable · 14 platform
Vulnerable SoftwareAffected Versions
All versions
All versions
Running on/withPlatform Versions
Mediatek
Mt6813
All versions
Mediatek
Mt6835
All versions
Mediatek
Mt6835t
All versions
Mediatek
Mt6878
All versions
Mediatek
Mt6878m
All versions
Mediatek
Mt6897
All versions
Mediatek
Mt6899
All versions
Mediatek
Mt6991
All versions
Mediatek
Mt8676
All versions
Mediatek
Mt8678
All versions
Mediatek
Mt8792
All versions
Mediatek
Mt8863
All versions
Mediatek
Mt8873
All versions
Mediatek
Mt8883
All versions

References (1)

Source: security@mediatek.com
Vendor Advisory

Timeline

No history available yet.