CVE-2025-20758: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673755; Issue ID: MSV-4647.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01673755
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20758?
CVE-2025-20758 is classified as a critical vulnerability due to its potential for remote denial of service.
How do I fix CVE-2025-20758?
To fix CVE-2025-20758, users should apply the latest security patches provided by MediaTek.
Is user interaction required to exploit CVE-2025-20758?
No, user interaction is not needed for exploitation of CVE-2025-20758.
What devices are affected by CVE-2025-20758?
CVE-2025-20758 affects various MediaTek NR series models, specifically NR15, NR16, NR17, and NR17R.
What type of vulnerability is CVE-2025-20758?
CVE-2025-20758 is a software vulnerability related to an uncaught exception that can cause a system crash.