In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01677581; Issue ID: MSV-4701.
History

Wed, 03 Dec 2025 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek mt2735
Mediatek mt6833
Mediatek mt6833p
Mediatek mt6853
Mediatek mt6853t
Mediatek mt6855
Mediatek mt6855t
Mediatek mt6873
Mediatek mt6875
Mediatek mt6875t
Mediatek mt6877
Mediatek mt6877t
Mediatek mt6877tt
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt8675
Mediatek mt8771
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8797
Mediatek nr15
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833p:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877tt:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek mt2735
Mediatek mt6833
Mediatek mt6833p
Mediatek mt6853
Mediatek mt6853t
Mediatek mt6855
Mediatek mt6855t
Mediatek mt6873
Mediatek mt6875
Mediatek mt6875t
Mediatek mt6877
Mediatek mt6877t
Mediatek mt6877tt
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt8675
Mediatek mt8771
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8797
Mediatek nr15

Tue, 02 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Dec 2025 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatk
Mediatk mt2735
Mediatk mt6833
Mediatk mt6833p
Mediatk mt6853
Mediatk mt6853t
Mediatk mt6855
Mediatk mt6855t
Mediatk mt6873
Mediatk mt6875
Mediatk mt6875t
Mediatk mt6877
Mediatk mt6877t
Mediatk mt6877tt
Mediatk mt6880
Mediatk mt6883
Mediatk mt6885
Mediatk mt6889
Mediatk mt6890
Mediatk mt6891
Mediatk mt6893
Mediatk mt8675
Mediatk mt8771
Mediatk mt8791
Mediatk mt8791t
Mediatk mt8797
Vendors & Products Mediatk
Mediatk mt2735
Mediatk mt6833
Mediatk mt6833p
Mediatk mt6853
Mediatk mt6853t
Mediatk mt6855
Mediatk mt6855t
Mediatk mt6873
Mediatk mt6875
Mediatk mt6875t
Mediatk mt6877
Mediatk mt6877t
Mediatk mt6877tt
Mediatk mt6880
Mediatk mt6883
Mediatk mt6885
Mediatk mt6889
Mediatk mt6890
Mediatk mt6891
Mediatk mt6893
Mediatk mt8675
Mediatk mt8771
Mediatk mt8791
Mediatk mt8791t
Mediatk mt8797

Tue, 02 Dec 2025 03:15:00 +0000

Type Values Removed Values Added
Description In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01677581; Issue ID: MSV-4701.
Weaknesses CWE-476
References

cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published: 2025-12-02T02:34:09.548Z

Updated: 2025-12-02T14:37:47.590Z

Reserved: 2024-11-01T01:21:50.402Z

Link: CVE-2025-20790

cve-icon Vulnrichment

Updated: 2025-12-02T14:37:42.835Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-02T03:16:19.907

Modified: 2025-12-03T20:32:19.967

Link: CVE-2025-20790

cve-icon Redhat

No data.