CVE-2025-20725: High severity MediaTek Lr12a vulnerability
In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01671924; Issue ID: MSV-4620.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01671924 - Compensating control
Given exploitation can occur via a rogue base station and requires no user interaction or additional execution privileges, restrict or monitor UE connectivity to base stations (e.g., detect/deny rogue base stations) to reduce exposure while patching.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20725?
CVE-2025-20725 has a high severity due to the potential for remote escalation of privilege without user interaction.
How do I fix CVE-2025-20725?
To fix CVE-2025-20725, ensure that your affected MediaTek device firmware is updated to the latest version provided by the vendor.
Which software is affected by CVE-2025-20725?
CVE-2025-20725 affects MediaTek LR12A, NR15, and NR16 among other specific MediaTek chipset models.
What are the potential impacts of CVE-2025-20725?
The impacts of CVE-2025-20725 can lead to remote privilege escalation when connected to a malicious base station.
Is user interaction required to exploit CVE-2025-20725?
No, user interaction is not required to exploit CVE-2025-20725.