CVE-2025-20709: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00415809; Issue ID: MSV-3405.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20709?
CVE-2025-20709 has a medium severity rating due to potential for escalation of privilege.
How do I fix CVE-2025-20709?
To fix CVE-2025-20709, apply the patch WCNCR00415809 as recommended by the vendor.
Which software versions are affected by CVE-2025-20709?
CVE-2025-20709 affects MediaTek Software Development Kit versions up to 7.6.7.2 and specific OpenWrt versions.
Can CVE-2025-20709 be exploited remotely?
Yes, CVE-2025-20709 can be exploited remotely without user interaction.
What could be the impact of exploiting CVE-2025-20709?
Exploitation of CVE-2025-20709 could lead to adjacent escalation of privilege on affected systems.