CVE-2025-20762

7.5

MediaTek · Modem

A reachable assertion in the MediaTek modem firmware allows an attacker to trigger a remote system crash via a rogue base station.

Executive summary

A critical vulnerability in MediaTek modem firmware could allow an attacker to trigger a remote denial of service on devices connected to a malicious base station.

Vulnerability

The flaw is a reachable assertion (CWE-617) within the modem component. An unauthenticated attacker operating a rogue base station can trigger a system crash without requiring user interaction or elevated privileges.

Business impact

This vulnerability poses a significant risk to operational continuity for mobile devices utilizing the affected MediaTek chipsets. Because the attack vector relies on a rogue base station, successful exploitation results in a remote denial of service, rendering the device unresponsive. Given the CVSS score of 7.5, this is a high-severity issue that could disrupt communications and mobile fleet availability if left unpatched.

Remediation

Immediate Action: Update the affected device firmware to the version containing the patch associated with MediaTek Patch ID MOLY01685181.

Proactive Monitoring: Monitor device telemetry for unexpected modem reboots or intermittent connectivity drops that may indicate interaction with a malicious radio environment.

Compensating Controls: While direct mitigation is limited for modem-level flaws, maintaining updated security software and avoiding connection to untrusted or suspicious public cellular networks can reduce exposure.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations deploying devices with the affected MediaTek chipsets should prioritize the deployment of vendor-supplied security patches. Given the potential for remote denial of service, administrators must ensure that firmware update cycles are strictly followed to mitigate the risk posed by this assertion flaw.

More MediaTek CVEs

Sources