CVE-2025-20704
CVSS Score
8.0
EPSS Score
0.0%
EPSS Percentile
0th
In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.
| CWE | CWE-787 |
| Vendor | mediatek, inc. |
| Product | mt6813, mt6835, mt6835t, mt6878, mt6878m, mt6897, mt6899, mt6991, mt8676, mt8678, mt8792, mt8863, mt8873, mt8883 |
| Published | Sep 1, 2025 |
| Last Updated | Feb 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for mediatek, inc. mt6813, mt6835, mt6835t, mt6878, mt6878m, mt6897, mt6899, mt6991, mt8676, mt8678, mt8792, mt8863, mt8873, mt8883
Be the first to know when new high vulnerabilities affecting mediatek, inc. mt6813, mt6835, mt6835t, mt6878, mt6878m, mt6897, mt6899, mt6991, mt8676, mt8678, mt8792, mt8863, mt8873, mt8883 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
MediaTek, Inc. / MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991, MT8676, MT8678, MT8792, MT8863, MT8873, MT8883
Modem NR17, NR17R