CVE-2025-20762
7.5MediaTek · Modem
A reachable assertion in the MediaTek modem firmware allows an attacker to trigger a remote system crash via a rogue base station.
Executive summary
A critical vulnerability in MediaTek modem firmware could allow an attacker to trigger a remote denial of service on devices connected to a malicious base station.
Vulnerability
The flaw is a reachable assertion (CWE-617) within the modem component. An unauthenticated attacker operating a rogue base station can trigger a system crash without requiring user interaction or elevated privileges.
Business impact
This vulnerability poses a significant risk to operational continuity for mobile devices utilizing the affected MediaTek chipsets. Because the attack vector relies on a rogue base station, successful exploitation results in a remote denial of service, rendering the device unresponsive. Given the CVSS score of 7.5, this is a high-severity issue that could disrupt communications and mobile fleet availability if left unpatched.
Remediation
Immediate Action: Update the affected device firmware to the version containing the patch associated with MediaTek Patch ID MOLY01685181.
Proactive Monitoring: Monitor device telemetry for unexpected modem reboots or intermittent connectivity drops that may indicate interaction with a malicious radio environment.
Compensating Controls: While direct mitigation is limited for modem-level flaws, maintaining updated security software and avoiding connection to untrusted or suspicious public cellular networks can reduce exposure.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations deploying devices with the affected MediaTek chipsets should prioritize the deployment of vendor-supplied security patches. Given the potential for remote denial of service, administrators must ensure that firmware update cycles are strictly followed to mitigate the risk posed by this assertion flaw.