CVE-2025-20732: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege (when OceReducedNeighborReport is disabled). User interaction is not needed for exploitation. Patch ID: WCNCR00441510; Issue ID: MSV-4139.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20732?
CVE-2025-20732 has a severity rating that indicates a potential local escalation of privilege due to an out of bounds write issue.
How do I fix CVE-2025-20732?
To fix CVE-2025-20732, update the affected MediaTek Software Development Kit or OpenWrt version to the latest patched release.
Is user interaction required to exploit CVE-2025-20732?
No, user interaction is not needed for the exploitation of CVE-2025-20732.
Which products are affected by CVE-2025-20732?
CVE-2025-20732 affects certain versions of the MediaTek Software Development Kit and OpenWrt 19.07.0 and 21.02.0.
What are the risks associated with CVE-2025-20732?
The risks associated with CVE-2025-20732 include potential local escalation of privilege for attackers with system privileges.