Description
In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01671924; Issue ID: MSV-4620.
Published: 2025-11-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Nov 2025 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Mediatek
Mediatek lr12a
Mediatek mt2735
Mediatek mt2737
Mediatek mt6739
Mediatek mt6761
Mediatek mt6762
Mediatek mt6762d
Mediatek mt6762m
Mediatek mt6763
Mediatek mt6765
Mediatek mt6765t
Mediatek mt6767
Mediatek mt6768
Mediatek mt6769
Mediatek mt6769k
Mediatek mt6769s
Mediatek mt6769t
Mediatek mt6769z
Mediatek mt6771
Mediatek mt6833
Mediatek mt6833p
Mediatek mt6853
Mediatek mt6853t
Mediatek mt6855
Mediatek mt6855t
Mediatek mt6873
Mediatek mt6875
Mediatek mt6875t
Mediatek mt6877
Mediatek mt6877t
Mediatek mt6877tt
Mediatek mt6879
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6886
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt6895
Mediatek mt6895tt
Mediatek mt6896
Mediatek mt6980
Mediatek mt6980d
Mediatek mt6983
Mediatek mt6983t
Mediatek mt6985
Mediatek mt6985t
Mediatek mt6989
Mediatek mt6989t
Mediatek mt6990
Mediatek mt8666
Mediatek mt8667
Mediatek mt8673
Mediatek mt8675
Mediatek mt8765
Mediatek mt8766
Mediatek mt8766r
Mediatek mt8768
Mediatek mt8771
Mediatek mt8786
Mediatek mt8788
Mediatek mt8788e
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8795t
Mediatek mt8797
Mediatek mt8798
Mediatek mt8893
Mediatek nr15
Mediatek nr16
CPEs cpe:2.3:h:mediatek:mt2735:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt2737:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6739:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6761:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6762:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6762d:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6762m:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6763:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6765t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6767:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769k:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769s:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6769z:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6833p:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6853t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6855t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6873:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6875t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6877tt:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6879:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6880:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6883:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6885:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6886:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6889:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6890:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6891:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6893:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6895tt:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6896:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6980d:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6983t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6985t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6989:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6989t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt6990:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8666:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8667:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8673:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8675:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8765:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8766r:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8768:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8771:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8786:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8788e:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8791t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8795t:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8797:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8798:-:*:*:*:*:*:*:*
cpe:2.3:h:mediatek:mt8893:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:lr12a:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr15:-:*:*:*:*:*:*:*
cpe:2.3:o:mediatek:nr16:-:*:*:*:*:*:*:*
Vendors & Products Mediatek
Mediatek lr12a
Mediatek mt2735
Mediatek mt2737
Mediatek mt6739
Mediatek mt6761
Mediatek mt6762
Mediatek mt6762d
Mediatek mt6762m
Mediatek mt6763
Mediatek mt6765
Mediatek mt6765t
Mediatek mt6767
Mediatek mt6768
Mediatek mt6769
Mediatek mt6769k
Mediatek mt6769s
Mediatek mt6769t
Mediatek mt6769z
Mediatek mt6771
Mediatek mt6833
Mediatek mt6833p
Mediatek mt6853
Mediatek mt6853t
Mediatek mt6855
Mediatek mt6855t
Mediatek mt6873
Mediatek mt6875
Mediatek mt6875t
Mediatek mt6877
Mediatek mt6877t
Mediatek mt6877tt
Mediatek mt6879
Mediatek mt6880
Mediatek mt6883
Mediatek mt6885
Mediatek mt6886
Mediatek mt6889
Mediatek mt6890
Mediatek mt6891
Mediatek mt6893
Mediatek mt6895
Mediatek mt6895tt
Mediatek mt6896
Mediatek mt6980
Mediatek mt6980d
Mediatek mt6983
Mediatek mt6983t
Mediatek mt6985
Mediatek mt6985t
Mediatek mt6989
Mediatek mt6989t
Mediatek mt6990
Mediatek mt8666
Mediatek mt8667
Mediatek mt8673
Mediatek mt8675
Mediatek mt8765
Mediatek mt8766
Mediatek mt8766r
Mediatek mt8768
Mediatek mt8771
Mediatek mt8786
Mediatek mt8788
Mediatek mt8788e
Mediatek mt8791
Mediatek mt8791t
Mediatek mt8795t
Mediatek mt8797
Mediatek mt8798
Mediatek mt8893
Mediatek nr15
Mediatek nr16

Tue, 04 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Mediatk
Mediatk mt2735
Mediatk mt2737
Mediatk mt6739
Mediatk mt6761
Mediatk mt6762
Mediatk mt6762d
Mediatk mt6762m
Mediatk mt6763
Mediatk mt6765
Mediatk mt6765t
Mediatk mt6767
Mediatk mt6768
Mediatk mt6769
Mediatk mt6769k
Mediatk mt6769s
Mediatk mt6769t
Mediatk mt6769z
Mediatk mt6771
Mediatk mt6833
Mediatk mt6833p
Mediatk mt6853
Mediatk mt6853t
Mediatk mt6855
Mediatk mt6855t
Mediatk mt6873
Mediatk mt6875
Mediatk mt6875t
Mediatk mt6877
Mediatk mt6877t
Mediatk mt6877tt
Mediatk mt6879
Mediatk mt6880
Mediatk mt6883
Mediatk mt6885
Mediatk mt6886
Mediatk mt6889
Mediatk mt6890
Mediatk mt6891
Mediatk mt6893
Mediatk mt6895
Mediatk mt6895tt
Mediatk mt6896
Mediatk mt6980
Mediatk mt6980d
Mediatk mt6983
Mediatk mt6983t
Mediatk mt6985
Mediatk mt6985t
Mediatk mt6989
Mediatk mt6989t
Mediatk mt6990
Mediatk mt8666
Mediatk mt8667
Mediatk mt8673
Mediatk mt8675
Mediatk mt8765
Mediatk mt8766
Mediatk mt8766r
Mediatk mt8768
Mediatk mt8771
Mediatk mt8786
Mediatk mt8788
Mediatk mt8788e
Mediatk mt8791
Mediatk mt8791t
Mediatk mt8795t
Mediatk mt8797
Mediatk mt8798
Mediatk mt8893
Vendors & Products Mediatk
Mediatk mt2735
Mediatk mt2737
Mediatk mt6739
Mediatk mt6761
Mediatk mt6762
Mediatk mt6762d
Mediatk mt6762m
Mediatk mt6763
Mediatk mt6765
Mediatk mt6765t
Mediatk mt6767
Mediatk mt6768
Mediatk mt6769
Mediatk mt6769k
Mediatk mt6769s
Mediatk mt6769t
Mediatk mt6769z
Mediatk mt6771
Mediatk mt6833
Mediatk mt6833p
Mediatk mt6853
Mediatk mt6853t
Mediatk mt6855
Mediatk mt6855t
Mediatk mt6873
Mediatk mt6875
Mediatk mt6875t
Mediatk mt6877
Mediatk mt6877t
Mediatk mt6877tt
Mediatk mt6879
Mediatk mt6880
Mediatk mt6883
Mediatk mt6885
Mediatk mt6886
Mediatk mt6889
Mediatk mt6890
Mediatk mt6891
Mediatk mt6893
Mediatk mt6895
Mediatk mt6895tt
Mediatk mt6896
Mediatk mt6980
Mediatk mt6980d
Mediatk mt6983
Mediatk mt6983t
Mediatk mt6985
Mediatk mt6985t
Mediatk mt6989
Mediatk mt6989t
Mediatk mt6990
Mediatk mt8666
Mediatk mt8667
Mediatk mt8673
Mediatk mt8675
Mediatk mt8765
Mediatk mt8766
Mediatk mt8766r
Mediatk mt8768
Mediatk mt8771
Mediatk mt8786
Mediatk mt8788
Mediatk mt8788e
Mediatk mt8791
Mediatk mt8791t
Mediatk mt8795t
Mediatk mt8797
Mediatk mt8798
Mediatk mt8893

Tue, 04 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Nov 2025 06:30:00 +0000

Type Values Removed Values Added
Description In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01671924; Issue ID: MSV-4620.
Weaknesses CWE-787
References

Subscriptions

Mediatek Lr12a Mt2735 Mt2737 Mt6739 Mt6761 Mt6762 Mt6762d Mt6762m Mt6763 Mt6765 Mt6765t Mt6767 Mt6768 Mt6769 Mt6769k Mt6769s Mt6769t Mt6769z Mt6771 Mt6833 Mt6833p Mt6853 Mt6853t Mt6855 Mt6855t Mt6873 Mt6875 Mt6875t Mt6877 Mt6877t Mt6877tt Mt6879 Mt6880 Mt6883 Mt6885 Mt6886 Mt6889 Mt6890 Mt6891 Mt6893 Mt6895 Mt6895tt Mt6896 Mt6980 Mt6980d Mt6983 Mt6983t Mt6985 Mt6985t Mt6989 Mt6989t Mt6990 Mt8666 Mt8667 Mt8673 Mt8675 Mt8765 Mt8766 Mt8766r Mt8768 Mt8771 Mt8786 Mt8788 Mt8788e Mt8791 Mt8791t Mt8795t Mt8797 Mt8798 Mt8893 Nr15 Nr16
Mediatk Mt2735 Mt2737 Mt6739 Mt6761 Mt6762 Mt6762d Mt6762m Mt6763 Mt6765 Mt6765t Mt6767 Mt6768 Mt6769 Mt6769k Mt6769s Mt6769t Mt6769z Mt6771 Mt6833 Mt6833p Mt6853 Mt6853t Mt6855 Mt6855t Mt6873 Mt6875 Mt6875t Mt6877 Mt6877t Mt6877tt Mt6879 Mt6880 Mt6883 Mt6885 Mt6886 Mt6889 Mt6890 Mt6891 Mt6893 Mt6895 Mt6895tt Mt6896 Mt6980 Mt6980d Mt6983 Mt6983t Mt6985 Mt6985t Mt6989 Mt6989t Mt6990 Mt8666 Mt8667 Mt8673 Mt8675 Mt8765 Mt8766 Mt8766r Mt8768 Mt8771 Mt8786 Mt8788 Mt8788e Mt8791 Mt8791t Mt8795t Mt8797 Mt8798 Mt8893
cve-icon MITRE

Status: PUBLISHED

Assigner: MediaTek

Published:

Updated: 2026-02-26T17:47:27.959Z

Reserved: 2024-11-01T01:21:50.392Z

Link: CVE-2025-20725

cve-icon Vulnrichment

Updated: 2025-11-04T15:09:33.776Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-04T07:15:32.113

Modified: 2025-11-05T17:16:11.350

Link: CVE-2025-20725

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-04T16:32:59Z

Weaknesses