CVE-2025-20667: Weak Encryption
In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01513293; Issue ID: MSV-2741.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20667?
CVE-2025-20667 is considered a medium severity vulnerability due to potential information disclosure risks.
How do I fix CVE-2025-20667?
To fix CVE-2025-20667, apply the latest firmware updates provided by MediaTek for the affected devices.
What types of devices are affected by CVE-2025-20667?
CVE-2025-20667 affects various MediaTek modem devices, including LR12A, LR13, NR15, NR16, and NR17 series.
Can CVE-2025-20667 be exploited remotely?
Yes, CVE-2025-20667 can be exploited remotely if a user connects to a rogue base station controlled by an attacker.
Is user interaction required to exploit CVE-2025-20667?
No, user interaction is not required to exploit CVE-2025-20667.