CVE-2025-20711: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00422399; Issue ID: MSV-3748.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20711?
CVE-2025-20711 is classified as a critical vulnerability due to the potential for remote escalation of privilege.
How do I fix CVE-2025-20711?
To fix CVE-2025-20711, apply the patch identified as WCNCR00422399 provided by MediaTek.
Which products are affected by CVE-2025-20711?
CVE-2025-20711 affects the MediaTek Software Development Kit versions up to 7.6.7.2 and specific versions of OpenWrt.
Can CVE-2025-20711 be exploited remotely?
Yes, CVE-2025-20711 can be exploited remotely without requiring user interaction.
Is user interaction needed for CVE-2025-20711 exploitation?
No, CVE-2025-20711 does not require user interaction for exploitation.