High severity8.0NVD Advisory· Published Sep 1, 2025· Updated Jun 17, 2026
CVE-2025-20704
CVE-2025-20704
Description
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- MediaTek, Inc./MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991, MT8676, MT8678, MT8792, MT8863, MT8873, MT8883v5Range: Modem NR17, NR17R
Patches
Vulnerability mechanics
References
1- corp.mediatek.com/product-security-bulletin/September-2025nvdVendor Advisory
News mentions
0No linked articles in our index yet.