CVE-2025-20735: High severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00435349; Issue ID: MSV-4051.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20735?
CVE-2025-20735 has the potential for local escalation of privilege due to an out of bounds write.
How do I fix CVE-2025-20735?
To mitigate CVE-2025-20735, apply the patch with ID WCNCR00435349 as soon as possible.
Which software versions are affected by CVE-2025-20735?
CVE-2025-20735 affects MediaTek Software Development Kit versions up to 7.6.7.2 and specific versions of OpenWrt including 19.07.0 and 21.02.0.
Is user interaction required for exploiting CVE-2025-20735?
No, user interaction is not needed for the exploitation of CVE-2025-20735.
What type of vulnerability is CVE-2025-20735?
CVE-2025-20735 is classified as an out of bounds write vulnerability that could lead to privilege escalation.