CVE-2025-20750: Null Pointer Dereference
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01661199; Issue ID: MSV-4296.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01661199 - Compensating control
Mitigate remote DoS exposure by preventing UEs from connecting to rogue base stations (e.g., restrict/monitor network access to trusted base stations and detect abnormal base-station behavior).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20750?
CVE-2025-20750 has been categorized as a high severity vulnerability due to the potential for remote denial of service.
How do I fix CVE-2025-20750?
To mitigate CVE-2025-20750, users should apply the latest security patch provided by MediaTek.
What types of devices are affected by CVE-2025-20750?
CVE-2025-20750 affects certain MediaTek devices that utilize the NR15 modem architecture.
Is user interaction required to exploit CVE-2025-20750?
No, exploitation of CVE-2025-20750 does not require any user interaction.
Can CVE-2025-20750 lead to data loss or leakage?
While CVE-2025-20750 primarily causes denial of service, it is advisable to treat any system crashes with caution as they may lead to unintended data loss.