Reachable assertion in MediaTek products - CVE-2025-20666
Published: May 5, 2025
Vulnerability identifier: #VU108513
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-20666
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: MediaTek
Affected software:
MT2735
MT6833
MT6833P
MT6855
MT6855T
MT6875T
MT6877T
MT6877TT
MT6880
MT6890
MT8666
MT8667
MT8673
MT8675
MT8771
MT8791
MT8791T
MT8795T
MT8798
MT6853
MT6853T
MT6873
MT6875
MT6877
MT6883
MT6885
MT6889
MT6891
MT6893
MT8797
MT2735
MT6833
MT6833P
MT6855
MT6855T
MT6875T
MT6877T
MT6877TT
MT6880
MT6890
MT8666
MT8667
MT8673
MT8675
MT8771
MT8791
MT8791T
MT8795T
MT8798
MT6853
MT6853T
MT6873
MT6875
MT6877
MT6883
MT6885
MT6889
MT6891
MT6893
MT8797
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in Modem. A remote attacker can cause a denial of service condition on the target system.
How to mitigate CVE-2025-20666
Install updates from vendor's website.