CVE-2025-20680: Critical severity MediaTek Nbiot Sdk vulnerability
Published Jul 8, 2025
·Updated
In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418044; Issue ID: MSV-3482.
Affected Software
7 affected components
All of the following
MediaTek Nbiot Sdk<=3.6
Any of the following
MediaTek Mt7902
MediaTek Mt7920
MediaTek Mt7921
MediaTek Mt7922
MediaTek Mt7925
MediaTek Mt7927
Event History
Jul 8, 2025
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Data Sourced
via NVD·03:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20680?
CVE-2025-20680 has a severity rating that indicates it can lead to local escalation of privilege.
2
How do I fix CVE-2025-20680?
To fix CVE-2025-20680, you should apply the patch ID WCNCR00418044 provided by MediaTek.
3
What causes CVE-2025-20680?
CVE-2025-20680 is caused by an incorrect bounds check in the Bluetooth driver.
4
Does CVE-2025-20680 require user interaction for exploitation?
No, CVE-2025-20680 does not require user interaction for exploitation.
5
Which software versions are affected by CVE-2025-20680?
CVE-2025-20680 affects MediaTek Nbiot SDK versions up to 3.6.