CVE-2025-20759: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01673760; Issue ID: MSV-4650.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01673760 - Compensating control
If UEs may have connected to a rogue base station, mitigate remote DoS risk by isolating/limiting connectivity to untrusted base stations (e.g., restrict/deny access to attacker-controlled networks) until the patch is applied.
- Operational
After applying patch MOLY01673760, re-check impacted Modem components for stability since remote DoS may have occurred from a previously connected rogue base station.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20759?
CVE-2025-20759 has a severity level that can lead to a remote denial of service.
How do I fix CVE-2025-20759?
To fix CVE-2025-20759, apply the recommended patches provided by MediaTek for the affected devices.
Who is affected by CVE-2025-20759?
CVE-2025-20759 affects devices using MediaTek NR15 and NR16 modems.
Can CVE-2025-20759 be exploited remotely?
Yes, CVE-2025-20759 can be exploited remotely without user interaction if a device connects to a rogue base station.
What happens during an exploit of CVE-2025-20759?
Exploitation of CVE-2025-20759 could result in a denial of service for the affected user's device.