CVE-2025-20712: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00422323; Issue ID: MSV-3810.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20712?
CVE-2025-20712 is classified as a potential escalation of privilege vulnerability.
How do I fix CVE-2025-20712?
To mitigate CVE-2025-20712, apply the patch ID WCNCR00422323 provided by MediaTek.
What causes CVE-2025-20712?
CVE-2025-20712 is caused by an incorrect bounds check in the wlan AP driver, leading to possible out of bounds writes.
Is user interaction required to exploit CVE-2025-20712?
No, user interaction is not needed for the exploitation of CVE-2025-20712.
Which software versions are affected by CVE-2025-20712?
CVE-2025-20712 affects versions of MediaTek Software Development Kit up to 8.3.1.1 and specific releases of OpenWrt.