CVE-2025-20708: High severity MediaTek Nr15 vulnerability
In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01123853; Issue ID: MSV-4131.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01123853 - Compensating control
If a UE may connect to rogue base stations controlled by an attacker, mitigate by preventing connections to untrusted/rogue base stations (e.g., using network/operator-side controls or trusted access policies so the UE does not attach to rogue base stations).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20708?
CVE-2025-20708 has a high severity rating due to the potential for remote privilege escalation.
How do I fix CVE-2025-20708?
To fix CVE-2025-20708, apply the security patch provided by MediaTek for affected devices.
Which devices are affected by CVE-2025-20708?
CVE-2025-20708 affects specific MediaTek NR series devices, including NR15, NR16, NR17, and NR17R.
Can CVE-2025-20708 be exploited without user interaction?
Yes, CVE-2025-20708 can be exploited remotely by connecting to a rogue base station without any user interaction.
What type of issue is described in CVE-2025-20708?
CVE-2025-20708 is related to an out-of-bounds write vulnerability due to incorrect bounds checking.