CVE-2025-20704

CVE-2025-20704

Vendor Mediatek, Inc.
Product MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991, MT8676, MT8678, MT8792, MT8863, MT8873, MT8883
Weakness CWE-787
Published September 1, 2025
Last update February 26, 2026

CVSS base score

What the vulnerability does

01Description

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: MOLY01516959; Issue ID: MSV-3502.

Key dates

02Disclosure timeline

September 1, 2025 CVE published
February 26, 2026 Record updated