First published: Mon Feb 03 2025(Updated: )
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00400889; Issue ID: MSV-2491.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
MediaTek Software Development Kit | <=7.4.0.1 | |
Any of | ||
MediaTek MT7603 Firmware | ||
MediaTek MT7615 Firmware | ||
MediaTek MT7622 Firmware | ||
Mediatek MT7915 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-20633 has the potential for remote code execution due to an out of bounds write issue.
To fix CVE-2025-20633, apply the patch identified by WCNCR00400889 as soon as possible.
CVE-2025-20633 affects versions of the MediaTek Software Development Kit up to 7.4.0.1.
Yes, exploitation of CVE-2025-20633 can occur without any user interaction needed.
Yes, CVE-2025-20633 allows for possible remote code execution from an adjacent attacker.