Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-20704

CVE-2025-20704: Mediatek Nr17 Privilege Escalation Flaw

CVE-2025-20704 is a privilege escalation vulnerability in Mediatek Nr17 caused by an out-of-bounds write in the modem. Attackers can exploit this via rogue base stations to gain elevated privileges remotely.

Published:

CVE-2025-20704 Overview

CVE-2025-20704 is an out-of-bounds write vulnerability in the MediaTek Modem component. The flaw stems from a missing bounds check during message processing in the cellular baseband stack. An attacker operating a rogue base station can trigger the write when a User Equipment (UE) device connects to the malicious cell. Successful exploitation enables remote escalation of privilege within the modem without additional execution privileges. User interaction is required to complete the attack chain. MediaTek tracks the fix as Patch ID MOLY01516959 and Issue ID MSV-3502, published in the September 2025 Product Security Bulletin.

Critical Impact

An adjacent-network attacker running a rogue base station can corrupt modem memory and escalate privileges on a connected device, threatening confidentiality, integrity, and availability of the baseband.

Affected Products

  • MediaTek modem firmware NR17 and NR17R
  • MediaTek SoCs MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991
  • MediaTek SoCs MT8676, MT8678, MT8792, MT8863, MT8873, MT8883

Discovery Timeline

  • 2025-09-01 - CVE-2025-20704 published to NVD
  • September 2025 - MediaTek releases security patch MOLY01516959 in the September 2025 Product Security Bulletin
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-20704

Vulnerability Analysis

The vulnerability is an out-of-bounds write [CWE-787] inside the MediaTek modem firmware. The affected code path processes data received over the cellular air interface without validating the size of the input against the destination buffer. When the modem accepts a crafted message from a rogue base station, the write overshoots its allocated buffer and corrupts adjacent memory regions in the modem address space.

Because the modem runs as a privileged real-time component handling NAS, RRC, and lower-layer signaling, memory corruption in this domain can translate into code execution within the baseband. The flaw allows remote escalation of privilege on the device once the UE attaches to the attacker-controlled cell. Exploitation requires user interaction, which in baseband attacks typically means the user enabling cellular connectivity or accepting a network condition that promotes attachment to the rogue cell.

Root Cause

The root cause is a missing bounds check before a memory write operation in the modem signaling handler. The firmware trusts a length or index field carried in a network-supplied message and uses it directly to compute a write offset or copy size. Without validation, attacker-controlled values produce writes outside the intended buffer.

Attack Vector

The attack vector is Adjacent Network (AV:A). An attacker stands up a rogue 4G/5G base station with parameters that cause nearby MediaTek-powered UEs to attach. Once a target device camps on the rogue cell, the attacker delivers the malformed signaling payload that triggers the out-of-bounds write. The vulnerability does not require authentication or pre-existing privileges on the device.

No public proof-of-concept exploit is currently available for CVE-2025-20704, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detailed exploitation specifics are described in the MediaTek Security Bulletin September 2025.

Detection Methods for CVE-2025-20704

Indicators of Compromise

  • Unexpected cellular reattachment events, repeated forced downgrades to lower radio access technologies, or attachment to cells with anomalous Mobile Country Code/Mobile Network Code (MCC/MNC) or Tracking Area Code (TAC) values.
  • Modem crash logs, ramdumps, or unexpected baseband resets on devices using affected MediaTek SoCs or NR17/NR17R modem firmware.
  • Abnormal radio environment near sensitive locations, including unknown cells broadcasting strong signal with non-operator identifiers.

Detection Strategies

  • Correlate device telemetry from mobile threat defense (MTD) agents to flag baseband resets, modem panics, or unsigned firmware events on affected MediaTek hardware.
  • Monitor enterprise mobility management (EMM/MDM) logs for clusters of devices attaching to unknown cells in the same geographic area.
  • Track patch level reporting against the MediaTek September 2025 bulletin to identify unpatched fleets running vulnerable modem builds.

Monitoring Recommendations

  • Ingest device, MDM, and MTD logs into a centralized analytics platform to baseline cellular attachment behavior and surface deviations.
  • Alert on devices reporting modem firmware versions predating Patch ID MOLY01516959 on the affected chipsets.
  • For high-risk users, monitor for indicators of rogue base station activity such as IMSI catcher detection events and sudden loss of mutual authentication.

How to Mitigate CVE-2025-20704

Immediate Actions Required

  • Inventory all mobile devices using affected MediaTek SoCs (MT6813, MT6835, MT6835T, MT6878, MT6878M, MT6897, MT6899, MT6991, MT8676, MT8678, MT8792, MT8863, MT8873, MT8883) and modem firmware NR17/NR17R.
  • Deploy the OEM security update incorporating MediaTek Patch ID MOLY01516959 as soon as the device vendor publishes a corresponding build.
  • Communicate user-facing guidance to avoid attaching to unknown or low-trust cellular networks until patches are applied.

Patch Information

MediaTek addressed the issue with Patch ID MOLY01516959 (Issue ID MSV-3502) in the MediaTek Security Bulletin September 2025. The fix must be delivered through downstream device OEMs as a firmware or full system update. Verify the device security patch level after installation to confirm the modem image has been refreshed.

Workarounds

  • Where supported, restrict cellular access to 5G Standalone with strong mutual authentication and disable legacy fallback for high-risk users.
  • Use airplane mode or Wi-Fi-only operation for sensitive devices in untrusted radio environments until firmware updates are available.
  • Enforce MDM policies that block use of unmanaged devices on affected chipsets when handling sensitive data until patched.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.