CVE-2025-20686: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415570; Issue ID: MSV-3404.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20686?
CVE-2025-20686 is classified as a critical vulnerability due to its potential for remote code execution.
What are the affected versions for CVE-2025-20686?
CVE-2025-20686 affects MediaTek Software Development Kit version up to 7.6.7.2 and OpenWrt version 19.07.0 and 21.02.0.
How do I fix CVE-2025-20686?
To fix CVE-2025-20686, update to the latest versions of the MediaTek Software Development Kit and OpenWrt that include the security patch.
What type of attack can exploit CVE-2025-20686?
CVE-2025-20686 can be exploited through a proximal or adjacent attack without requiring additional execution privileges.
Is user interaction needed for exploiting CVE-2025-20686?
No, user interaction is not needed for the exploitation of CVE-2025-20686.