CVE-2025-20646: Input Validation
Published Mar 3, 2025
·Updated
In wlan AP FW, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00389074; Issue ID: MSV-1803.
Affected Software
6 affected components
All of the following
MediaTek Software Development Kit<7.6.7.2
Any of the following
MediaTek Mt6890
MediaTek MT7915
MediaTek Mt7916
MediaTek Mt7981
MediaTek Mt7986
Event History
Mar 3, 2025
CVE Published
via MITRE·02:25 AM
Data Sourced
via MITRE·02:25 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20646?
CVE-2025-20646 is considered to have high severity due to potential remote escalation of privilege.
2
How do I fix CVE-2025-20646?
The recommended fix for CVE-2025-20646 is to apply Patch ID WCNCR00389074.
3
Which software versions are affected by CVE-2025-20646?
CVE-2025-20646 affects the Mediatek Software Development Kit versions prior to 7.6.7.2.
4
Is user interaction required to exploit CVE-2025-20646?
No, user interaction is not required to exploit CVE-2025-20646.
5
What type of vulnerability is CVE-2025-20646?
CVE-2025-20646 is an out of bounds write vulnerability due to improper input validation.