CVE-2025-20647: Null Pointer Dereference
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00791311 / MOLY01067019; Issue ID: MSV-2721.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20647?
The severity of CVE-2025-20647 is classified as critical due to its potential to cause a remote denial of service.
How do I fix CVE-2025-20647?
To fix CVE-2025-20647, you need to apply the latest patch provided by MediaTek for the affected products.
What products are impacted by CVE-2025-20647?
CVE-2025-20647 impacts MediaTek NR12A, NR13, NR15, and NR16 models among others.
Is user interaction required to exploit CVE-2025-20647?
No, user interaction is not required to exploit CVE-2025-20647, as it can be remotely triggered.
What is the potential impact of CVE-2025-20647?
The potential impact of CVE-2025-20647 is a system crash leading to remote denial of service for devices connected to a rogue base station.