CVE-2025-20761: Medium severity MediaTek Nr15 vulnerability
In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01311265; Issue ID: MSV-4655.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20761?
CVE-2025-20761 has a severity level that can lead to a remote denial of service due to incorrect error handling.
How do I fix CVE-2025-20761?
To mitigate CVE-2025-20761, apply the latest security patch provided by MediaTek for affected versions.
What is the potential impact of CVE-2025-20761?
The potential impact of CVE-2025-20761 is a system crash that could disrupt services if exploited through a rogue base station.
Who is affected by CVE-2025-20761?
CVE-2025-20761 affects users of MediaTek NR15, NR16, and NR17 modems.
Is user interaction needed to exploit CVE-2025-20761?
No, user interaction is not needed for the exploitation of CVE-2025-20761.