CVE-2025-20708

8.1

MediaTek · Modem (Various Chipsets)

A MediaTek modem vulnerability allows remote escalation of privilege via an out-of-bounds write when a device connects to a rogue base station.

Executive summary

An out-of-bounds write vulnerability in MediaTek modems, tracked as CVE-2025-20708, permits unauthenticated remote escalation of privilege without user interaction.

Vulnerability

The flaw is an out-of-bounds write (CWE-787) occurring within the modem firmware due to an incorrect bounds check. This allows an attacker operating a rogue base station to achieve remote escalation of privilege against unauthenticated devices.

Business impact

A successful exploit grants an attacker elevated privileges on the mobile device, potentially leading to full system compromise, data exfiltration, or persistent unauthorized access. With a CVSS score of 8.1, the high severity reflects the ability of an attacker to bypass standard security controls without requiring user interaction, posing a significant risk to organizational mobility security.

Remediation

Immediate Action: Apply the vendor-provided firmware update (Patch ID: MOLY01123853) through official OEM update channels as soon as the manufacturer makes it available for your specific device.

Proactive Monitoring: Monitor device security logs for unusual modem behavior or unexpected network connectivity patterns that may indicate interaction with malicious base stations.

Compensating Controls: While specific network-level controls are difficult for mobile devices, users should avoid connecting to untrusted or public Wi-Fi and cellular networks in high-risk environments.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of modem-level vulnerabilities and the potential for privilege escalation, administrators should prioritize the deployment of security patches released by their mobile device vendors. Ensure that all devices utilizing the affected MediaTek chipsets are updated to the latest firmware version to mitigate the risk of unauthorized access via rogue base station attacks.

More MediaTek CVEs

Sources