CVE-2025-20751: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01661195; Issue ID: MSV-4297.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01661195
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20751?
CVE-2025-20751 is classified as a vulnerability that can lead to remote denial of service.
How do I fix CVE-2025-20751?
To fix CVE-2025-20751, users should apply the patch provided by MediaTek as soon as it becomes available.
What causes CVE-2025-20751?
CVE-2025-20751 is caused by a missing bounds check in the modem, which can lead to potential system crashes.
Is user interaction required to exploit CVE-2025-20751?
No, user interaction is not needed for exploitation of CVE-2025-20751.
Which devices are affected by CVE-2025-20751?
Devices using specific MediaTek chipsets, such as the MediaTek Nr15, are affected by CVE-2025-20751.