PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-20761 MediaTek, Inc. CVE debrief

A vulnerability in Mediatek's Modem could lead to a system crash due to incorrect error handling if a device connects to a rogue base station controlled by an attacker. This issue requires no additional execution privileges and no user interaction for exploitation. The vulnerability affects Mediatek-based devices, particularly those in environments where connections to untrusted or rogue base stations are possible. Defenders and security teams should assess exposure and prioritize patching to prevent potential exploitation and operational disruption.

Vendor
MediaTek, Inc.
Product
MediaTek chipset
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-06
Original CVE updated
2026-09-30
Advisory published
2026-01-06
Advisory updated
2026-09-30

Who should care

Defenders and security teams responsible for Mediatek-based devices, especially those in environments where devices may connect to untrusted or rogue base stations, should assess exposure and prioritize patching.

Why it matters

CVE-2025-20761 is a Mediatek Modem vulnerability leading to potential system crashes and denial of service. Defenders should verify exposure, prioritize patching, and monitor for exploitation attempts due to the risk of unnoticed attacks and operational disruption.

  • Denial of service could disrupt critical operations relying on Mediatek Modem devices.
  • Verification of device exposure and patch application is necessary to prevent potential exploitation.
  • Successful exploitation requires no user interaction, increasing the risk of unnoticed attacks.
  • Remediation priority is elevated due to the potential for widespread impact on device availability.

Technical summary

CVE-2025-20761 is a vulnerability in Mediatek's Modem due to incorrect error handling, potentially leading to a system crash and remote denial of service if exploited by connecting to a rogue base station. No user interaction or additional privileges are required for exploitation. The vulnerability has been assigned a CVSS score of 6.5 and a severity of MEDIUM. The CVE record was published on 2026-01-06T02:15:41.680Z and has not been modified since then. Defenders should prioritize verifying exposure of Mediatek Modem devices, especially those in environments where connections to untrusted base stations are possible, and apply patches as available.

Defensive priority

Defenders should prioritize verifying exposure of Mediatek Modem devices, especially those in environments where connections to untrusted base stations are possible, and apply patches as available.

Recommended defensive actions

  • Verify and apply the patch (Patch ID: MOLY01311265) to Mediatek Modem devices.
  • Assess exposure of Mediatek Modem devices in the environment, especially those susceptible to connections with rogue base stations.
  • Monitor for and respond to potential denial of service attempts.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The CVE and NVD records provide details on the vulnerability, its potential impact, and reference a vendor advisory for further information. The vulnerability is identified as CVE-2025-20761, with a Patch ID of MOLY01311265 and Issue ID MSV-4655. The Mediatek advisory (Patch ID: MOLY01311265) should be consulted for specific details on affected products and recommended actions. Defenders should verify the exposure of Mediatek Modem devices, especially those susceptible to connections with rogue base stations, and apply patches as they

Sources and references

Verified primary and authoritative sources

  • CVE-2025-20761 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-20761

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-20761 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-20761

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.