CVE-2025-20790: Null Pointer Dereference
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01677581; Issue ID: MSV-4701.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch MOLY01677581
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20790?
CVE-2025-20790 has the potential for a remote denial of service, making it a critical security vulnerability due to its ability to cause system crashes.
How do I fix CVE-2025-20790?
To fix CVE-2025-20790, users should apply the latest software patches provided by MediaTek for their affected devices.
What causes CVE-2025-20790?
CVE-2025-20790 is caused by improper input validation in the modem, which can be exploited by connecting to a rogue base station.
Who is affected by CVE-2025-20790?
CVE-2025-20790 affects certain MediaTek modem devices that are susceptible to remote exploitation.
Is user interaction needed to exploit CVE-2025-20790?
No, CVE-2025-20790 can be exploited without any user interaction, making it a significant risk.