First published: Mon Mar 03 2025(Updated: )
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.
Credit: security@mediatek.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Any of | ||
Mediatek Linkit Software Development Kit | <=3.6 | |
Open edX | =23.05 | |
Any of | ||
MediaTek MT6880 | ||
MediaTek MT6890 | ||
MediaTek MT6980D | ||
MediaTek MT6990 | ||
MediaTek MT7663 Firmware | ||
MediaTek MT7902 | ||
Mediatek Mt7925 | ||
MediaTek MT7927 | ||
Mediatek Mt7961 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-20649 has a medium severity rating due to its potential for information disclosure.
To mitigate CVE-2025-20649, apply patch ID WCNCR00396437 as suggested by Mediatek.
CVE-2025-20649 affects the Bluetooth Stack SW within specific versions of MediaTek SDK and OpenWRT.
Yes, CVE-2025-20649 can be exploited remotely without any user interaction.
The impact of CVE-2025-20649 is the potential for unauthorized information disclosure in Bluetooth communications.