CVE-2025-20754: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to an incorrect bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689251; Issue ID: MSV-4840.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01689251
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20754?
CVE-2025-20754 has been rated as a medium severity vulnerability due to its potential to cause a remote denial of service.
How do I fix CVE-2025-20754?
To fix CVE-2025-20754, users should apply the latest security patch provided by MediaTek for their affected devices.
What devices are impacted by CVE-2025-20754?
CVE-2025-20754 impacts MediaTek NR15, NR16, NR17, and NR17R devices among others.
Can CVE-2025-20754 be exploited remotely?
Yes, CVE-2025-20754 can be exploited remotely by connecting to a rogue base station without requiring user interaction.
What are the potential consequences of CVE-2025-20754?
The potential consequence of CVE-2025-20754 is a system crash which could lead to a denial of service for users connected to an affected device.