CVE-2025-20731: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441511; Issue ID: MSV-4140.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20731?
The severity of CVE-2025-20731 is considered high due to the potential for local privilege escalation.
How do I fix CVE-2025-20731?
To fix CVE-2025-20731, update to the latest version of the MediaTek Software Development Kit or the impacted OpenWrt versions.
Who is vulnerable to CVE-2025-20731?
CVE-2025-20731 affects systems running specific versions of the MediaTek Software Development Kit and OpenWrt.
What type of attack is CVE-2025-20731 related to?
CVE-2025-20731 is related to local escalation of privilege due to an out of bounds write.
Is user interaction required to exploit CVE-2025-20731?
No, user interaction is not needed for the exploitation of CVE-2025-20731.