CVE-2025-20632: High severity mediatek linkit software development kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00397139; Issue ID: MSV-2188.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20632?
CVE-2025-20632 has a high severity due to the potential for local escalation of privilege without the need for additional execution privileges.
How do I fix CVE-2025-20632?
To mitigate CVE-2025-20632, apply the patch ID WCNCR00397139 as recommended by MediaTek.
Who is affected by CVE-2025-20632?
CVE-2025-20632 affects users of the Mediatek Software Development Kit versions up to and including 7.6.7.2.
Is user interaction required for exploiting CVE-2025-20632?
No, user interaction is not required to exploit CVE-2025-20632.
What type of vulnerability is CVE-2025-20632?
CVE-2025-20632 is classified as an out of bounds write vulnerability in the wlan AP driver.