VYPR
High severity8.0NVD Advisory· Published Sep 1, 2025· Updated Jun 17, 2026

CVE-2025-20704

CVE-2025-20704

Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:mediatek:nr17:-:*:*:*:*:*:*:*
  • cpe:2.3:o:mediatek:nr17r:-:*:*:*:*:*:*:*
  • Mediatek/Modemllm-fuzzy
  • MediaTek, Inc./MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991, MT8676, MT8678, MT8792, MT8863, MT8873, MT8883v5
    Range: Modem NR17, NR17R

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.