CVE-2025-20716: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421149; Issue ID: MSV-3728.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20716?
CVE-2025-20716 is considered a vulnerability that can lead to local escalation of privilege.
How do I fix CVE-2025-20716?
CVE-2025-20716 can be fixed by applying the patch identified as WCNCR00421149.
What software is affected by CVE-2025-20716?
CVE-2025-20716 affects the MediaTek Software Development Kit version 7.6.7.2 and specific OpenWrt versions 19.07.0 and 21.02.0.
Is user interaction required to exploit CVE-2025-20716?
No, user interaction is not needed for exploitation of CVE-2025-20716.
Can CVE-2025-20716 lead to remote execution?
CVE-2025-20716 does not lead to remote execution but allows escalation of privilege if system-level access is already obtained.