CVE-2025-20649: Medium severity mediatek linkit software development kit vulnerability
In Bluetooth Stack SW, there is a possible information disclosure due to a missing permission check. This could lead to remote (proximal/adjacent) information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00396437; Issue ID: MSV-2184.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20649?
CVE-2025-20649 has a medium severity rating due to its potential for information disclosure.
How do I fix CVE-2025-20649?
To mitigate CVE-2025-20649, apply patch ID WCNCR00396437 as suggested by Mediatek.
What does CVE-2025-20649 affect?
CVE-2025-20649 affects the Bluetooth Stack SW within specific versions of MediaTek SDK and OpenWRT.
Can CVE-2025-20649 be exploited without user interaction?
Yes, CVE-2025-20649 can be exploited remotely without any user interaction.
What could be the impact of CVE-2025-20649?
The impact of CVE-2025-20649 is the potential for unauthorized information disclosure in Bluetooth communications.