CVE-2025-20756: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to a logic error. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673749; Issue ID: MSV-4643.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01673749 - Compensating control
Mitigate remote DoS risk by preventing/limiting UE connectivity to rogue base stations (e.g., use network access controls/monitoring to detect and block rogue base stations).
- Compensating control
Since no user interaction is needed for exploitation, ensure affected Modem devices have network protections in place (e.g., block suspicious or unauthorized base-station connections via network filtering/ACLs).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20756?
CVE-2025-20756 has a severity that could result in remote denial of service due to a system crash.
How do I fix CVE-2025-20756?
To fix CVE-2025-20756, apply the patch identified as MOLY01673.
What systems are affected by CVE-2025-20756?
CVE-2025-20756 affects MediaTek NR15 modems when connected to rogue base stations.
Is user interaction required to exploit CVE-2025-20756?
No, user interaction is not needed to exploit CVE-2025-20756.
What can an attacker achieve by exploiting CVE-2025-20756?
An attacker can achieve a remote denial of service, causing a system crash.