← Back

CVE-2025-20654

nvd nist
Published: Apr 7, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

In wlan service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00406897; Issue ID: MSV-2875.

Affected (10)

7 products
Software Development Kit
Mt7622
Mt7915
Mt7916
Mt7981
Mt7986
Mt6890
1 product
Openwrt
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.4.0.1
All versions
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.6.7.0
All versions
All versions
All versions
All versions
Configuration C
3 vulnerable
Vulnerable SoftwareAffected Versions
Openwrt
Version 19.07.0
Version 21.02.0
All versions

References (1)

Source: security@mediatek.com
Vendor Advisory

Timeline

No history available yet.