CVE-2025-20704

8.8

MediaTek · Modem

A missing bounds check in the MediaTek modem firmware allows for an out of bounds write, potentially leading to remote privilege escalation when connected to a rogue base station.

Executive summary

A critical out of bounds write vulnerability in MediaTek modem firmware could allow an attacker to achieve remote privilege escalation via a rogue base station.

Vulnerability

This vulnerability is an out of bounds write (CWE-787) occurring within the modem firmware. An unauthenticated attacker can trigger this flaw if a device connects to a malicious base station, requiring user interaction to facilitate the connection.

Business impact

The potential for remote privilege escalation poses a severe threat to the integrity and confidentiality of mobile devices utilizing the affected MediaTek chipsets. With a CVSS score of 8.8, this vulnerability carries a high risk of total system compromise, potentially allowing an attacker to gain unauthorized control over device functions or sensitive user data.

Remediation

Immediate Action: Apply the vendor security update associated with Patch ID MOLY01516959 provided in the September 2025 MediaTek security bulletin.

Proactive Monitoring: Monitor device connectivity logs for unusual network handovers or frequent disconnections that might indicate interaction with unauthorized base station equipment.

Compensating Controls: While standard WAF solutions do not apply to modem firmware, users should exercise caution when connecting to untrusted or public cellular networks in high-risk environments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for remote privilege escalation and the critical nature of modem firmware, organizations should prioritize the deployment of the MOLY01516959 patch. Ensure all mobile device management policies include verification of security patch levels to mitigate the risk of exploitation by rogue base stations.

More MediaTek CVEs

Sources