MediaTek, a leading provider of chipset technology for smartphones, tablets, AIoT, and smart TVs, has released critical patches addressing several security vulnerabilities across its product portfolio.
The newly published MediaTek Product Security Bulletin details the flaws, their potential impacts, and the extensive range of affected devices.
Device manufacturers were notified of these vulnerabilities and provided security patches at least two months before the public disclosure.
The security risks were assessed using the Common Vulnerability Scoring System version 3.1 (CVSS v3.1).
CVE | Title | Severity | Type |
CVE-2025-20666 | Reachable assertion in Modem | High | DoS |
CVE-2025-20667 | Inadequate encryption strength in Modem | Medium | Info Disclosure (ID) |
CVE-2025-20671 | Out-of-bounds write in thermal | Medium | Elevation of Priv. |
CVE-2025-20668 | Out-of-bounds write in scp | Medium | Elevation of Priv. |
CVE-2025-20670 | Improper certificate validation in Modem | Medium | Info Disclosure (ID) |
CVE-2025-20665 | File and directory info exposure in devinfo | Medium | Info Disclosure (ID) |
Of particular concern is CVE-2025-20666, which may allow an attacker to trigger a remote denial-of-service simply by connecting a user device to a malicious base station.
Also notable are multiple medium-severity vulnerabilities, including encryption weaknesses and improper certificate handling that could expose sensitive information under specific conditions.
MediaTek has coordinated with OEMs to ensure patch availability ahead of disclosure, minimizing exposure risks for users.
The company recommends all device owners install the latest firmware as soon as it becomes available.
Experts advise users to:
- Regularly update device firmware and security patches
- Avoid connecting to unknown or suspicious networks
- Stay alert for abnormal device behavior or connectivity issues
MediaTek’s continued transparency and prompt action demonstrate a commitment to device security.
Users are urged to stay proactive in keeping their devices secure by applying available updates and following best security practices.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!