CVE-2025-20760

7.5

MediaTek · MediaTek chipset

A reachable assertion in the MediaTek modem firmware allows unauthenticated attackers to cause a remote denial of service via a rogue base station.

Executive summary

A critical vulnerability in MediaTek chipsets could allow an unauthenticated attacker to trigger a remote denial of service by forcing a device to connect to a malicious base station.

Vulnerability

The vulnerability is a reachable assertion (CWE-617) within the modem firmware, triggered by an uncaught exception that leads to a read of uninitialized heap data. An unauthenticated attacker operating a rogue base station can trigger this condition without user interaction to crash the device modem.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a high risk to availability. Successful exploitation results in a remote denial of service, rendering mobile devices unable to communicate, which poses significant operational risks for critical infrastructure and mobile-dependent business workflows.

Remediation

Immediate Action: Update affected devices to the firmware version containing patch ID MOLY01676750 as provided in the January 2026 MediaTek security bulletin.

Proactive Monitoring: Monitor device connectivity logs for unexpected disconnections or frequent modem resets which may indicate interaction with an unauthorized cellular base station.

Compensating Controls: Ensure device firmware is managed through centralized MDM policies and avoid connecting to untrusted or public cellular networks where possible.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for remote denial of service on mobile devices, organizations should prioritize firmware updates for all mobile assets utilizing the affected MediaTek chipsets. Administrators must verify that the specific patch ID MOLY01676750 is applied to restore modem stability and prevent exploitation.

More MediaTek CVEs

Sources