CVE-2025-20793

7.5

MediaTek · Modem

A NULL pointer dereference in the MediaTek modem firmware allows an attacker to trigger a remote system crash via a rogue base station.

Executive summary

A critical vulnerability in MediaTek modem firmware enables remote denial of service attacks without requiring user interaction or authentication.

Vulnerability

The vulnerability is a NULL pointer dereference (CWE-476) within the modem firmware. It can be triggered by an unauthenticated attacker controlling a rogue base station, causing the device to crash and resulting in a denial of service.

Business impact

The ability to remotely crash a mobile device modem leads to significant service disruption and loss of connectivity. With a CVSS score of 7.5, this high severity flaw poses a risk to business continuity, particularly for mobile-dependent operations, as it requires no user interaction to execute.

Remediation

Immediate Action: Organizations and users must apply the manufacturer security update (Patch ID: MOLY01430930) as provided in the January 2026 MediaTek security bulletin.

Proactive Monitoring: Monitor device logs for unexpected modem resets or intermittent connectivity loss that could indicate proximity to malicious radio environments.

Compensating Controls: Since this is a low-level firmware vulnerability, traditional WAFs are not applicable; ensure that device management policies restrict connections to known secure networks where possible.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the high impact on device availability and the remote nature of the exploit, administrators should prioritize the deployment of the provided firmware patches. Affected devices should be updated immediately to eliminate the risk of remote denial of service attacks.

More MediaTek CVEs

Sources