CVE-2025-20633: High severity mediatek linkit software development kit vulnerability
Published Feb 3, 2025
·Updated
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.
Affected Software
5 affected components
All of the following
MediaTek Software Development Kit<=7.4.0.1
Any of the following
MediaTek Mt7603
MediaTek MT7615
MediaTek MT7622
MediaTek MT7915
Event History
Feb 3, 2025
CVE Published
via MITRE·03:23 AM
Data Sourced
via MITRE·03:23 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20633?
CVE-2025-20633 has the potential for remote code execution due to an out of bounds write issue.
2
How do I fix CVE-2025-20633?
To fix CVE-2025-20633, apply the patch identified by WCNCR00400889 as soon as possible.
3
What software is affected by CVE-2025-20633?
CVE-2025-20633 affects versions of the MediaTek Software Development Kit up to 7.4.0.1.
4
Can exploitation of CVE-2025-20633 occur without user interaction?
Yes, exploitation of CVE-2025-20633 can occur without any user interaction needed.
5
Is remote code execution possible due to CVE-2025-20633?
Yes, CVE-2025-20633 allows for possible remote code execution from an adjacent attacker.