CVE-2025-20667

HIGH

Mediatek Lr12a - Weak Encryption

Title source: rule
STIX 2.1

Description

In Modem, there is a possible information disclosure due to incorrect error handling. This could lead to remote information disclosure, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01513293; Issue ID: MSV-2741.

Scores

CVSS v3 7.5
EPSS 0.0042
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-326
Status published
Products (6)
mediatek/lr12a
mediatek/lr13
mediatek/nr15
mediatek/nr16
mediatek/nr17
mediatek/nr17r
Published May 05, 2025
Tracked Since Feb 18, 2026