CVE-2025-20704: High severity MediaTek Nr17 vulnerability
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01516959
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20704?
CVE-2025-20704 has a high severity due to the potential for remote escalation of privilege through an out of bounds write.
How do I fix CVE-2025-20704?
To fix CVE-2025-20704, ensure that the firmware is updated to the latest version provided by MediaTek that addresses this vulnerability.
Who is affected by CVE-2025-20704?
Devices using MediaTek NR17 and NR17r are affected by CVE-2025-20704.
What is the impact of CVE-2025-20704?
The impact of CVE-2025-20704 includes the possibility of unauthorized privilege escalation when connected to a rogue base station.
Is user interaction required to exploit CVE-2025-20704?
Yes, user interaction is required to exploit CVE-2025-20704.