Reachable assertion in MediaTek products - CVE-2025-20666
Published: May 5, 2025
Vulnerability identifier: #VU108513
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-20666
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in Modem. A remote attacker can cause a denial of service condition on the target system.
Affected software
MT6885
MT8797
MT6893
MT6891
MT6889
MT6883
MT6877
MT6875
MT6873
MT6853T
MT6853
MT8798
MT8795T
MT8791T
MT8791
MT8771
MT8675
MT8673
MT8667
MT8666
MT6890
MT2735
MT6880
MT6877TT
MT6877T
MT6875T
MT6855T
MT6855
MT6833P
MT6833
MT8797
MT6893
MT6891
MT6889
MT6883
MT6877
MT6875
MT6873
MT6853T
MT6853
MT8798
MT8795T
MT8791T
MT8791
MT8771
MT8675
MT8673
MT8667
MT8666
MT6890
MT2735
MT6880
MT6877TT
MT6877T
MT6875T
MT6855T
MT6855
MT6833P
MT6833
How to mitigate CVE-2025-20666
Install updates from vendor's website.