CVE-2025-20674: Critical severity OpenWrt OpenWrt vulnerability
In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00413202; Issue ID: MSV-3303.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20674?
CVE-2025-20674 has a high severity due to its potential for remote escalation of privilege.
How do I fix CVE-2025-20674?
To fix CVE-2025-20674, apply the patch identified by Patch ID WCNCR00413202.
What systems are affected by CVE-2025-20674?
CVE-2025-20674 affects MediaTek firmware versions 7.6.7.2 for multiple products including MT7986, MT7990, MT7992, MT7993, MT7915, and MT7916.
Is user interaction required for exploiting CVE-2025-20674?
Exploitation of CVE-2025-20674 does not require user interaction.
What could be the consequence of CVE-2025-20674 exploitation?
Exploitation of CVE-2025-20674 could lead to arbitrary packet injection and potentially escalate privileges on the affected systems.