CVE-2025-20717: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00419946; Issue ID: MSV-3582.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20717?
CVE-2025-20717 has been classified as a medium severity vulnerability due to its potential for local escalation of privilege.
How do I fix CVE-2025-20717?
To fix CVE-2025-20717, apply the patch identified by Patch ID WCNCR00419946.
What software is affected by CVE-2025-20717?
CVE-2025-20717 affects the MediaTek Software Development Kit versions up to 7.6.7.2 and specific versions of OpenWrt (19.07.0 and 21.02.0).
Can CVE-2025-20717 be exploited without user interaction?
Yes, exploitation of CVE-2025-20717 does not require user interaction, making it more critical.
What type of vulnerability is CVE-2025-20717?
CVE-2025-20717 is an out-of-bounds write vulnerability in the wlan AP driver.