6.5

CVE-2025-20762

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01685181; Issue ID: MSV-4760.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mediatek ≫ Nr17 Version -
   Mediatek ≫ Mt6835 Version -
   Mediatek ≫ Mt6835t Version -
   Mediatek ≫ Mt6878 Version -
   Mediatek ≫ Mt6878m Version -
   Mediatek ≫ Mt6897 Version -
   Mediatek ≫ Mt6899 Version -
   Mediatek ≫ Mt6991 Version -
   Mediatek ≫ Mt8676 Version -
   Mediatek ≫ Mt8678 Version -
   Mediatek ≫ Mt8755 Version -
   Mediatek ≫ Mt8792 Version -
   Mediatek ≫ Mt8793 Version -
   Mediatek ≫ Mt8863 Version -
   Mediatek ≫ Mt8873 Version -
   Mediatek ≫ Mt8883 Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.188
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 6.5 2.8 3.6
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

https://corp.mediatek.com/product-security-bulletin/January-2026
Vendor Advisory