Out-of-bounds write in MediaTek products - CVE-2025-20704
Published: September 1, 2025
Vulnerability identifier: #VU114606
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-20704
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vendor: MediaTek
Affected software:
MT6813
MT6835
MT6835T
MT6878
MT6878M
MT6897
MT6899
MT6991
MT8676
MT8678
MT8792
MT8863
MT8873
MT8883
MT6813
MT6835
MT6835T
MT6878
MT6878M
MT6897
MT6899
MT6991
MT8676
MT8678
MT8792
MT8863
MT8873
MT8883
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a boundary error when processing untrusted input within the Modem component. A remote attacker with control over a rogue base station can trigger an out-of-bounds write and execute arbitrary code on the target system.
How to mitigate CVE-2025-20704
Install updates from vendor's website.