In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01677581; Issue ID: MSV-4701.
Metrics
Affected Vendors & Products
References
History
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mediatk
Mediatk mt2735 Mediatk mt6833 Mediatk mt6833p Mediatk mt6853 Mediatk mt6853t Mediatk mt6855 Mediatk mt6855t Mediatk mt6873 Mediatk mt6875 Mediatk mt6875t Mediatk mt6877 Mediatk mt6877t Mediatk mt6877tt Mediatk mt6880 Mediatk mt6883 Mediatk mt6885 Mediatk mt6889 Mediatk mt6890 Mediatk mt6891 Mediatk mt6893 Mediatk mt8675 Mediatk mt8771 Mediatk mt8791 Mediatk mt8791t Mediatk mt8797 |
|
| Vendors & Products |
Mediatk
Mediatk mt2735 Mediatk mt6833 Mediatk mt6833p Mediatk mt6853 Mediatk mt6853t Mediatk mt6855 Mediatk mt6855t Mediatk mt6873 Mediatk mt6875 Mediatk mt6875t Mediatk mt6877 Mediatk mt6877t Mediatk mt6877tt Mediatk mt6880 Mediatk mt6883 Mediatk mt6885 Mediatk mt6889 Mediatk mt6890 Mediatk mt6891 Mediatk mt6893 Mediatk mt8675 Mediatk mt8771 Mediatk mt8791 Mediatk mt8791t Mediatk mt8797 |
Tue, 02 Dec 2025 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01677581; Issue ID: MSV-4701. | |
| Weaknesses | CWE-476 | |
| References |
|
Status: PUBLISHED
Assigner: MediaTek
Published: 2025-12-02T02:34:09.548Z
Updated: 2025-12-02T14:37:47.590Z
Reserved: 2024-11-01T01:21:50.402Z
Link: CVE-2025-20790
Updated: 2025-12-02T14:37:42.835Z
Status : Received
Published: 2025-12-02T03:16:19.907
Modified: 2025-12-02T15:15:53.833
Link: CVE-2025-20790
No data.