CVE-2025-20713: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00432661; Issue ID: MSV-3904.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20713?
CVE-2025-20713 has a high severity due to potential local escalation of privilege.
How do I fix CVE-2025-20713?
You can fix CVE-2025-20713 by applying the patch ID WCNCR00432661.
Who is affected by CVE-2025-20713?
CVE-2025-20713 affects users of the MediaTek Software Development Kit versions up to 7.6.7.2 and specific OpenWrt versions.
Can CVE-2025-20713 be exploited without user interaction?
Yes, CVE-2025-20713 can be exploited without user interaction if the malicious actor has system privileges.
What type of vulnerability is CVE-2025-20713?
CVE-2025-20713 is an out of bounds write vulnerability caused by an incorrect bounds check in the wlan AP driver.