CVE-2025-20720: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00418954; Issue ID: MSV-3569.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20720?
CVE-2025-20720 has a high severity rating due to the potential for remote escalation of privilege.
How do I fix CVE-2025-20720?
To fix CVE-2025-20720, apply the patch identified by WCNCR00418954 available from MediaTek.
What systems are affected by CVE-2025-20720?
CVE-2025-20720 affects the MediaTek Software Development Kit versions up to and including 7.6.7.2 and specific versions of OpenWrt.
Can CVE-2025-20720 be exploited without user interaction?
Yes, CVE-2025-20720 can be exploited without any user interaction required.
What type of vulnerability is CVE-2025-20720?
CVE-2025-20720 is an out of bounds write vulnerability that can lead to privilege escalation.