CVE-2025-20685: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00416226; Issue ID: MSV-3409.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20685?
CVE-2025-20685 is a high-severity vulnerability that can lead to remote code execution without additional privileges.
How do I fix CVE-2025-20685?
To fix CVE-2025-20685, apply the available patch with ID WCNCR00416226 as soon as possible.
Which software is affected by CVE-2025-20685?
CVE-2025-20685 affects MediaTek Software Development Kit versions up to 7.6.7.2 and OpenWrt version 19.07.0 and 21.02.0.
Can CVE-2025-20685 be exploited without user interaction?
Yes, CVE-2025-20685 can be exploited remotely without requiring user interaction.
What is the nature of the vulnerability in CVE-2025-20685?
CVE-2025-20685 is an out of bounds write caused by an incorrect bounds check in the wlan AP driver.