CVE-2025-20718: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00419945; Issue ID: MSV-3581.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20718?
The severity of CVE-2025-20718 is high due to the potential for local escalation of privilege from an out of bounds write.
How do I fix CVE-2025-20718?
To fix CVE-2025-20718, apply the patch identified by Patch ID WCNCR00419945.
Is user interaction required to exploit CVE-2025-20718?
No, user interaction is not needed for the exploitation of CVE-2025-20718.
What software versions are affected by CVE-2025-20718?
CVE-2025-20718 affects specific versions of the MediaTek Software Development Kit up to 7.6.7.2 and OpenWrt versions 19.07.0 and 21.02.0.
What hardware is vulnerable to CVE-2025-20718?
CVE-2025-20718 specifically affects devices using certain versions of the MediaTek software stack, but numerous hardware devices listed are not vulnerable.