CVE-2025-20794Medium· 6.5▾ SunlitIn Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges n…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01689259 / MOLY01586470; Issue ID: MSV-4847.
nr15nr16nr17nr17rRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-20793Medium· 6.5In Modem, there is a possible system crash due to incorrect error handling
CVE-2025-20760Medium· 6.5In Modem, there is a possible read of uninitialized heap data due to an uncaught exception
CVE-2025-20761Medium· 6.5In Modem, there is a possible system crash due to incorrect error handling
CVE-2025-20762Medium· 6.5In Modem, there is a possible system crash due to incorrect error handling
CVE-2025-20755Medium· 5.3In Modem, there is a possible application crash due to improper input validation
CVE-2025-20797High· 7.8In battery, there is a possible out of bounds write due to a missing bounds check