CVE-2025-20726
7.5MediaTek · Modem
A heap-based out of bounds write vulnerability in MediaTek modems allows for remote privilege escalation when connected to a rogue base station.
Executive summary
A heap overflow vulnerability in MediaTek modems, classified with a CVSS score of 7.5, could allow an attacker to achieve remote privilege escalation without user interaction.
Vulnerability
This is a heap overflow (CWE-122) caused by an incorrect bounds check within the modem firmware. An attacker can trigger this vulnerability by deploying a rogue base station, requiring no user interaction and low privileges.
Business impact
Successful exploitation of this vulnerability permits an attacker to perform remote privilege escalation, potentially granting them unauthorized control over the device communication layer. Given the CVSS score of 7.5, this represents a significant risk to data confidentiality, integrity, and system availability. Compromise at this level could lead to unauthorized access to sensitive user data and persistent control over the affected mobile device.
Remediation
Immediate Action: Apply the vendor-provided security update corresponding to Patch ID MOLY01672598, as detailed in the November 2025 MediaTek product security bulletin.
Proactive Monitoring: Monitor device connection logs for unusual base station handovers or unexpected modem behavior that may indicate interaction with malicious radio environments.
Compensating Controls: While standard network-level WAFs are ineffective against radio-based attacks, ensure that device firmware integrity checks are enabled and that security patches are deployed via the device manufacturer's update channel.
Exploitation status
Public Exploit Available: exploit_available (false)
Analyst recommendation
This vulnerability presents a high risk due to the potential for remote code execution at the modem firmware level. Organizations and users should prioritize the deployment of firmware updates provided by their device manufacturer. Failure to patch leaves the device susceptible to compromise when connecting to malicious cellular infrastructure.