CVE-2025-20666: High severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00650610; Issue ID: MSV-2933.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20666?
The severity of CVE-2025-20666 is high due to its potential to cause a remote denial of service.
How do I fix CVE-2025-20666?
To fix CVE-2025-20666, users must apply the appropriate security patches provided by MediaTek.
What systems are affected by CVE-2025-20666?
CVE-2025-20666 affects devices running Mediatek LR15, specifically when connected to untrusted base stations.
What kind of attack is possible with CVE-2025-20666?
CVE-2025-20666 can be exploited by an attacker connecting a rogue base station, causing a system crash.
Is user interaction required to exploit CVE-2025-20666?
No, user interaction is not needed for exploiting CVE-2025-20666.