CVE-2025-20670: Medium severity MediaTek Nr16 vulnerability
In Modem, there is a possible permission bypass due to improper certificate validation. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with User execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01334347; Issue ID: MSV-2772.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20670?
CVE-2025-20670 has a severity rating that indicates a significant risk of remote information disclosure due to permission bypass from improper certificate validation.
How do I fix CVE-2025-20670?
To fix CVE-2025-20670, ensure that you apply the latest patch provided by MediaTek for the affected NR16 and NR17 models.
Who is affected by CVE-2025-20670?
CVE-2025-20670 affects users of MediaTek NR16 and NR17 devices that may connect to rogue base stations due to improper certificate validation.
What is the impact of CVE-2025-20670?
The impact of CVE-2025-20670 can lead to remote information disclosure if a user connects to a malicious base station.
Is user interaction required to exploit CVE-2025-20670?
Yes, user interaction is required for exploiting CVE-2025-20670, as the vulnerability needs the user to connect to a rogue base station.