CVE-2025-20794
7.5MediaTek · MediaTek chipset
A stack overflow vulnerability in the MediaTek modem firmware allows an unauthenticated attacker to trigger a remote system crash via a rogue base station.
Executive summary
A critical stack overflow vulnerability in MediaTek chipsets enables unauthenticated remote denial of service attacks without user interaction.
Vulnerability
The flaw is a stack overflow (CWE-121) caused by improper input validation within the modem firmware. An unauthenticated attacker can exploit this by connecting a user equipment device to a rogue base station, resulting in a system crash.
Business impact
The potential for remote denial of service poses a significant risk to operational continuity, particularly for mobile devices relying on these chipsets. With a CVSS score of 7.5, this high severity vulnerability could lead to widespread service disruption, impacting communication capabilities and rendering devices unresponsive.
Remediation
Immediate Action: Apply the vendor security updates containing Patch IDs MOLY01689259 or MOLY01586470 as provided in the MediaTek product security bulletin.
Proactive Monitoring: Monitor device logs for unusual modem behavior or unexpected reboots that may indicate exploitation attempts.
Compensating Controls: While standard WAFs cannot mitigate radio level attacks, organizations should ensure that mobile device management policies restrict connections to known or trusted cellular infrastructure where possible.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote denial of service and the lack of user interaction required for exploitation, this vulnerability presents a notable risk to mobile device availability. Administrators and device manufacturers should prioritize the deployment of the specified patches to address the underlying stack overflow and restore system integrity.