CVE-2025-20715: High severity MediaTek Software Development Kit vulnerability
Published Oct 14, 2025
·Updated
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421152; Issue ID: MSV-3731.
Affected Software
12 affected components
All of the following
MediaTek Software Development Kit<=7.6.7.2
Any of the following
MediaTek Mt6890
MediaTek MT7615
MediaTek MT7622
MediaTek Mt7663
MediaTek MT7915
MediaTek Mt7916
MediaTek Mt7981
MediaTek Mt7986
All of the following
Any of the following
OpenWrt OpenWrt=19.07.0
OpenWrt OpenWrt=21.02.0
MediaTek Mt6890
Event History
Oct 14, 2025
CVE Published
via MITRE·09:11 AM
Data Sourced
via MITRE·09:11 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-20715?
CVE-2025-20715 has a severity that allows local escalation of privilege due to an out of bounds write.
2
How do I fix CVE-2025-20715?
To fix CVE-2025-20715, apply the patch identified by Patch ID WCNCR00421152.
3
What causes CVE-2025-20715?
CVE-2025-20715 is caused by an incorrect bounds check in the wlan AP driver.
4
Is user interaction required to exploit CVE-2025-20715?
No, user interaction is not needed for exploiting CVE-2025-20715.
5
Which software versions are affected by CVE-2025-20715?
CVE-2025-20715 affects MediaTek's Software Development Kit versions up to 7.6.7.2 and specific versions of OpenWrt.