#VU108513 Reachable assertion in MediaTek products - CVE-2025-20666
Published: May 5, 2025
Vulnerability identifier: #VU108513
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-20666
CWE-ID: CWE-617
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
MT2735
MT6833
MT6833P
MT6855
MT6855T
MT6875T
MT6877T
MT6877TT
MT6880
MT6890
MT8666
MT8667
MT8673
MT8675
MT8771
MT8791
MT8791T
MT8795T
MT8798
MT6853
MT6853T
MT6873
MT6875
MT6877
MT6883
MT6885
MT6889
MT6891
MT6893
MT8797
MT2735
MT6833
MT6833P
MT6855
MT6855T
MT6875T
MT6877T
MT6877TT
MT6880
MT6890
MT8666
MT8667
MT8673
MT8675
MT8771
MT8791
MT8791T
MT8795T
MT8798
MT6853
MT6853T
MT6873
MT6875
MT6877
MT6883
MT6885
MT6889
MT6891
MT6893
MT8797
Software vendor:
MediaTek
MediaTek
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion in Modem. A remote attacker can cause a denial of service condition on the target system.
Remediation
Install updates from vendor's website.