First published: Mon Feb 03 2025(Updated: )
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01289384; Issue ID: MSV-2436.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
mediatek nr16 | ||
MediaTek NR17 | ||
Mediatek NR17R | ||
Any of | ||
MediaTek MT2737 | ||
MediaTek MT6813 | ||
MediaTek MT6835 | ||
Mediatek MT6835T | ||
MediaTek MT6878 | ||
MediaTek MT6878M | ||
MediaTek MT6879 | ||
MediaTek MT6886 | ||
MediaTek MT6895 | ||
Mediatek Mt6895tt | ||
MediaTek MT6896 | ||
MediaTek MT6897 | ||
Mediatek Mt6899 | ||
MediaTek MT6980D | ||
MediaTek MT6980D | ||
MediaTek MT6983 | ||
MediaTek MT6983T | ||
MediaTek MT6985T | ||
MediaTek MT6985T | ||
MediaTek MT6989 | ||
Mediatek MT6989T | ||
MediaTek MT6990 | ||
Mediatek MT6991 | ||
MediaTek MT8673 | ||
MediaTek MT8676 | ||
MediaTek MT8678 | ||
MediaTek MT8795T | ||
MediaTek MT8798 | ||
MediaTek MT8863 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-20634 is categorized as a critical vulnerability due to the potential for remote code execution.
To fix CVE-2025-20634, users should apply the latest security patches provided by MediaTek for the affected devices.
CVE-2025-20634 affects specific MediaTek modem versions including NR16, NR17, and NR17R.
No, user interaction is not needed for the exploitation of CVE-2025-20634.
If exploited, CVE-2025-20634 could allow attackers to execute arbitrary code on devices connected to a rogue base station.