CVE-2025-20792: Input Validation
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01717526; Issue ID: MSV-5591.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Modemto a version that resolves this vulnerability.Patch MOLY01717526
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20792?
CVE-2025-20792 has a high severity rating due to its potential to cause a remote denial of service.
How do I fix CVE-2025-20792?
To fix CVE-2025-20792, apply the latest security patch provided by MediaTek for affected devices.
What can be compromised due to CVE-2025-20792?
CVE-2025-20792 could lead to a system crash when a user equipment connects to a rogue base station.
Is user interaction required to exploit CVE-2025-20792?
No, user interaction is not needed for the exploitation of CVE-2025-20792.
Which products are affected by CVE-2025-20792?
CVE-2025-20792 affects various MediaTek modem products, particularly those in the NR15 family.