CVE-2025-20752: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01270690; Issue ID: MSV-4301.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01270690 - Compensating control
Mitigate remote denial of service by preventing UE connections to rogue base stations (e.g., restrict/monitor network access so devices do not attach to unauthorized base stations).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20752?
CVE-2025-20752 has a high severity rating due to its potential to cause a denial of service.
How do I fix CVE-2025-20752?
To fix CVE-2025-20752, apply the latest security patch provided by MediaTek as soon as it is available.
What devices are affected by CVE-2025-20752?
CVE-2025-20752 primarily affects MediaTek Nr15, Nr16, Nr17, and Nr17r software versions.
Can CVE-2025-20752 be exploited without user interaction?
Yes, CVE-2025-20752 can be exploited remotely without requiring any user interaction.
What impact does CVE-2025-20752 have on systems?
CVE-2025-20752 could result in a system crash and denial of service when exploited.