CVE-2025-20755: Null Pointer Dereference
In Modem, there is a possible application crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00628396; Issue ID: MSV-4775.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY00628396 - Compensating control
Mitigate remote DoS risk by preventing UEs from connecting to rogue/unauthorized base stations (e.g., restrict/monitor network access so devices cannot attach to attacker-controlled base stations).
- Operational
Verify Modem stability after installing Patch ID MOLY00628396 and monitor for application crashes consistent with Issue ID MSV-4775.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20755?
The severity of CVE-2025-20755 has not been officially assigned yet, but it involves a potential denial of service risk due to improper input validation.
How do I fix CVE-2025-20755?
To fix CVE-2025-20755, ensure that any impacted MediaTek devices are updated to the latest firmware version provided by the manufacturer.
What impact does CVE-2025-20755 have on my device?
CVE-2025-20755 can lead to remote denial of service, causing the application to crash when connected to a rogue base station.
Is user interaction required to exploit CVE-2025-20755?
No, user interaction is not needed to exploit CVE-2025-20755, making it more critical to address.
Which devices are affected by CVE-2025-20755?
CVE-2025-20755 affects various MediaTek chipsets, particularly those in the nr15 product line.