CVE-2025-20726: High severity MediaTek Lr12a vulnerability
In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01672598; Issue ID: MSV-4622.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01672598 - Compensating control
If possible, prevent UEs from connecting to rogue base stations by restricting/monitoring network access (e.g., operator controls, network isolation, or radio/network access filtering) since exploitation requires no additional execution privileges and no user interaction.
- Compensating control
Implement or ensure detection/mitigation for rogue base station connections (e.g., network monitoring/alerts and rapid isolation of affected UEs) because exploitation can occur after a UE connects to an attacker-controlled rogue base station.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20726?
The severity of CVE-2025-20726 is classified as critical due to the potential for remote escalation of privilege by an attacker.
How do I fix CVE-2025-20726?
To fix CVE-2025-20726, apply the security patches provided by MediaTek for the affected modem products.
What types of devices are affected by CVE-2025-20726?
CVE-2025-20726 affects MediaTek modem products like NR15, NR16, NR17, and others listed in the vulnerability database.
Can CVE-2025-20726 be exploited without user interaction?
Yes, CVE-2025-20726 can be exploited remotely without user interaction, posing a significant risk.
What are the consequences of exploiting CVE-2025-20726?
Exploiting CVE-2025-20726 could allow an attacker to gain elevated privileges on devices connected to rogue base stations.