CVE-2025-20760: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible read of uninitialized heap data due to an uncaught exception. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01676750; Issue ID: MSV-4653.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20760?
The severity of CVE-2025-20760 is high due to the potential for remote denial of service without user interaction.
How do I fix CVE-2025-20760?
To fix CVE-2025-20760, update your MediaTek devices to the latest firmware version that addresses the vulnerability.
What systems are affected by CVE-2025-20760?
CVE-2025-20760 affects MediaTek NR15, NR16, and NR17 software platforms.
Can CVE-2025-20760 be exploited remotely?
Yes, CVE-2025-20760 can be exploited remotely if a user equipment connects to a rogue base station.
Is user interaction required to exploit CVE-2025-20760?
No, user interaction is not required to exploit CVE-2025-20760.