CVE-2025-20644: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible memory corruption due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01525673; Issue ID: MSV-2747.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20644?
CVE-2025-20644 is classified with a high severity due to its potential to cause remote denial of service.
How do I fix CVE-2025-20644?
To fix CVE-2025-20644, update to the latest version of the affected MediaTek software that includes security patches.
What devices are affected by CVE-2025-20644?
CVE-2025-20644 affects MediaTek NR15 and NR16 devices, among others.
Does CVE-2025-20644 require user interaction for exploitation?
No, CVE-2025-20644 can be exploited without any user interaction.
What are the risks associated with CVE-2025-20644?
The risks associated with CVE-2025-20644 include potential remote denial of service attacks via rogue base stations.