CVE-2025-20678: Medium severity MediaTek Lr12a vulnerability
In ims service, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01394606; Issue ID: MSV-2739.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20678?
The severity of CVE-2025-20678 is considered high due to the potential for remote denial of service.
How do I fix CVE-2025-20678?
To fix CVE-2025-20678, you should update the affected MediaTek devices to the latest firmware version that addresses this vulnerability.
What impact does CVE-2025-20678 have on affected devices?
CVE-2025-20678 can cause a system crash on affected devices when connected to a rogue base station, leading to a remote denial of service.
Is user interaction required to exploit CVE-2025-20678?
No, user interaction is not required to exploit CVE-2025-20678, making it particularly concerning.
Which devices are affected by CVE-2025-20678?
CVE-2025-20678 affects several MediaTek products, including models like Lr12a, Lr13, Nr15, Nr16, and Nr17.