CVE-2025-20736: Medium severity MediaTek Software Development Kit vulnerability
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00435347; Issue ID: MSV-4049.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-20736?
CVE-2025-20736 has a high severity rating and may allow local privilege escalation for users with system privileges.
How do I fix CVE-2025-20736?
To fix CVE-2025-20736, apply the patch identified as WCNCR00435347.
What are the affected software versions for CVE-2025-20736?
CVE-2025-20736 affects MediaTek Software Development Kit up to version 7.6.7.2 and specific versions of OpenWrt (19.07.0 and 21.02.0).
Is user interaction required to exploit CVE-2025-20736?
User interaction is not needed to exploit CVE-2025-20736, making the vulnerability particularly concerning.
What could be the consequence of exploiting CVE-2025-20736?
Exploiting CVE-2025-20736 could lead to local escalation of privileges for a malicious actor who has already obtained system privilege.