CVE-2025-20637: High severity mediatek linkit software development kit vulnerability
Published Feb 3, 2025
·Updated
In network HW, there is a possible system hang due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00399035; Issue ID: MSV-2380.
Affected Software
3 affected components
All of the following
MediaTek Software Development Kit<=7.6.7.0
Any of the following
MediaTek Mt7981
MediaTek Mt7986
Event History
Feb 3, 2025
CVE Published
via MITRE·03:23 AM
Data Sourced
via MITRE·03:23 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20637?
CVE-2025-20637 is classified as a critical vulnerability due to its potential for remote denial of service.
2
How do I fix CVE-2025-20637?
To fix CVE-2025-20637, apply the patch identified as WCNCR00399035.
3
What are the affected versions for CVE-2025-20637?
CVE-2025-20637 affects the MediaTek Software Development Kit versions up to and including 7.6.7.0.
4
Does CVE-2025-20637 require user interaction for exploitation?
No, CVE-2025-20637 does not require user interaction for exploitation.
5
What can be the impact of exploiting CVE-2025-20637?
The exploitation of CVE-2025-20637 can lead to a system hang, causing a denial of service remotely.